First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 134512
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: SpanKY <vapier@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Milan Holzäpfel <public@mjh.name>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
dropbear-0.47-r1_0.48.1.ebuild.diff Diff from dropbear-0.47-r1.ebuild to my dropbear-0.48.1.ebuild patch Milan Holzäpfel 2006-05-27 05:41 0000 757 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 134512 depends on: Show dependency tree
Show dependency graph
Bug 134512 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-27 05:38 0000
Hello, 

A new version of dropbear is available.  It reduces the delays one is likely to
get on non-busy, dedicated servers on log-in, mainly caused by waiting for
/dev/random. 
I will attach a patch from the 0.47-r1 ebuild to the 0.48.1-one I successfully
used.  It removes dropbear-0.47-CVE-2006-0225.patch (see ChangeLog of Dropbear)
and renames the tar.bz2 into tar.gz, as no tar.bz2 is available on the Dropbear
site. 



Full ChangeLog:
0.48.1 - Sat 11 March 2006

- Compile fix for scp

0.48 - Thurs 9 March 2006

- Check that the circular buffer is properly empty before
  closing a channel, which could cause truncated transfers
  (thanks to Tomas Vanek for helping track it down)

- Implement per-IP pre-authentication connection limits 
  (after some poking from Pablo Fernandez)

- Exit gracefully if trying to connect to as SSH v1 server 
  (reported by Rushi Lala)

- Only read /dev/random once at startup when in non-inetd mode

- Allow ctrl-c to close a dbclient password prompt (may
  still have to press enter on some platforms)

- Merged in uClinux patch for inetd mode

- Updated to scp from OpenSSH 4.3p2 - fixes a security issue
  where use of system() could cause users to execute arbitrary
  code through malformed filenames, ref CVE-2006-0225



Regards,
Milan

------- Comment #1 From Milan Holzäpfel 2006-05-27 05:41:13 0000 -------
Created an attachment (id=87637) [edit]
Diff from dropbear-0.47-r1.ebuild to my dropbear-0.48.1.ebuild

- Rename source files from tar.bz2 to tar.gz (no tar.bz2 available)
- Remove dropbear-0.47-CVE-2006-0225.patch (fix is included in this release)

------- Comment #2 From SpanKY 2006-06-07 06:07:35 0000 -------
in portage, thanks

First Last Prev Next    No search results available      Search page      Enter new bug