dropbear: security bump to 2016.72
authorPeter Korsgaard <peter@korsgaard.com>
Thu, 10 Mar 2016 13:35:55 +0000 (14:35 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 10 Mar 2016 13:35:55 +0000 (14:35 +0100)
2016.72 - 9 March 2016

- Validate X11 forwarding input. Could allow bypass of authorized_keys command= restrictions,
  found by github.com/tintinweb. Thanks to Damien Miller for a patch.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/dropbear/dropbear.hash
package/dropbear/dropbear.mk

index 934b26b85c957cf2e9c2ec749fafeb312b4f5080..82872441d77eb8246c4f128d97aceb418569ad4a 100644 (file)
@@ -1,2 +1,2 @@
 # From https://matt.ucc.asn.au/dropbear/releases/SHA256SUM.asc
-sha256 376214169c0e187ee9f48ae1a99b3f835016ad5b98ede4bfd1cf581deba783af  dropbear-2015.71.tar.bz2
+sha256 9323766d3257699fd7d6e7b282c5a65790864ab32fd09ac73ea3d46c9ca2d681  dropbear-2016.72.tar.bz2
index e7633ae8bd92ce1bdb18d0e22d1f8a3a5915bd3d..4ba94c3a7119f7783dcd67acf0a556b9bc34656f 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-DROPBEAR_VERSION = 2015.71
+DROPBEAR_VERSION = 2016.72
 DROPBEAR_SITE = http://matt.ucc.asn.au/dropbear/releases
 DROPBEAR_SOURCE = dropbear-$(DROPBEAR_VERSION).tar.bz2
 DROPBEAR_LICENSE = MIT, BSD-2c-like, BSD-2c