diff options
| author | Peter Korsgaard <peter@korsgaard.com> | 2017-10-26 14:52:47 +0200 |
|---|---|---|
| committer | Peter Korsgaard <peter@korsgaard.com> | 2017-10-27 13:49:02 +0200 |
| commit | 70663a9a4fcb9211fcef7668a8a35de11cc54775 (patch) | |
| tree | 91a810cbf900f54e3d9cb2e4a1c3d869bb533e6f | |
| parent | 751cd4cfab88ff15143d13eccf87f982a274e4e3 (diff) | |
| download | buildroot-70663a9a4fcb9211fcef7668a8a35de11cc54775.tar.gz buildroot-70663a9a4fcb9211fcef7668a8a35de11cc54775.zip | |
openssh: security bump to version 7.6p1
Fixes CVE-2017-15906 - The process_open function in sftp-server.c in OpenSSH
before 7.6 does not properly prevent write operations in readonly mode,
which allows attackers to create zero-length files.
For more details, see the release notes:
https://www.openssh.com/txt/release-7.6
Also add a hash for the license file while we're at it.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
| -rw-r--r-- | package/openssh/openssh.hash | 6 | ||||
| -rw-r--r-- | package/openssh/openssh.mk | 2 |
2 files changed, 5 insertions, 3 deletions
diff --git a/package/openssh/openssh.hash b/package/openssh/openssh.hash index 3685bc0dbf..d8a4da32ad 100644 --- a/package/openssh/openssh.hash +++ b/package/openssh/openssh.hash @@ -1,2 +1,4 @@ -# From http://www.openssh.com/txt/release-7.5 (base64 encoded) -sha256 9846e3c5fab9f0547400b4d2c017992f914222b3fd1f8eee6c7dc6bc5e59f9f0 openssh-7.5p1.tar.gz +# From http://www.openssh.com/txt/release-7.6 (base64 encoded) +sha256 a323caeeddfe145baaa0db16e98d784b1fbc7dd436a6bf1f479dfd5cd1d21723 openssh-7.6p1.tar.gz +# Locally calculated +sha256 05a4c25ef464e19656c5259bd4f4da8428efab01044f3541b79fbb3ff209350f LICENCE diff --git a/package/openssh/openssh.mk b/package/openssh/openssh.mk index 38a32bf54d..6b7ac22c19 100644 --- a/package/openssh/openssh.mk +++ b/package/openssh/openssh.mk @@ -4,7 +4,7 @@ # ################################################################################ -OPENSSH_VERSION = 7.5p1 +OPENSSH_VERSION = 7.6p1 OPENSSH_SITE = http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable OPENSSH_LICENSE = BSD-3-Clause, BSD-2-Clause, Public Domain OPENSSH_LICENSE_FILES = LICENCE |

