diff options
author | Baruch Siach <baruch@tkos.co.il> | 2019-01-15 13:17:53 +0200 |
---|---|---|
committer | Peter Korsgaard <peter@korsgaard.com> | 2019-01-15 19:49:22 +0100 |
commit | 8233c666124890fff713ecb254993b52b1fa7674 (patch) | |
tree | 4905511788912541ee0481127c9eb76256f6df0a /package/libinput/0001-meson.build-enable-CPP-include-check-only-in-case-CP.patch | |
parent | bd0bb8b8f6c975de3c926359990da9308d08a9e0 (diff) | |
download | buildroot-8233c666124890fff713ecb254993b52b1fa7674.tar.gz buildroot-8233c666124890fff713ecb254993b52b1fa7674.zip |
package/openssh: add upstream security fix
Fixes CVE-2018-20685: The scp client allows server to modify permissions
of the target directory by using empty ("D0777 0 \n") or dot ("D0777 0
.\n") directory name.
The bug reporter lists a number of related vulnerabilities that are not
fixed yet:
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'package/libinput/0001-meson.build-enable-CPP-include-check-only-in-case-CP.patch')
0 files changed, 0 insertions, 0 deletions