Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 28971 - lsh-1.4.2.ebuild (New Package)
Summary: lsh-1.4.2.ebuild (New Package)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: x86 Linux
: High normal (vote)
Assignee: SpanKY
URL:
Whiteboard:
Keywords: EBUILD
Depends on: 28973
Blocks:
  Show dependency tree
 
Reported: 2003-09-17 04:58 UTC by Justin Heesemann
Modified: 2004-07-11 04:17 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
lsh-1.4.2.ebuild (lsh-1.4.2.ebuild,876 bytes, application/octet-stream)
2003-09-17 04:59 UTC, Justin Heesemann
Details
lsh-1.4.2.ebuild (lsh-1.4.2.ebuild,876 bytes, text/plain)
2003-09-17 04:59 UTC, Justin Heesemann
Details
lsh-1.4.2.ebuild (lsh-1.4.2.ebuild,876 bytes, text/plain)
2003-09-17 05:01 UTC, Justin Heesemann
Details
init script (lshd.rc6,416 bytes, text/plain)
2003-09-17 05:03 UTC, Justin Heesemann
Details
/etc/conf.d/lshd (lshd.conf_d,51 bytes, text/plain)
2003-09-17 05:04 UTC, Justin Heesemann
Details
version 1.4.3 fixes security problem (lsh-1.4.3.ebuild,876 bytes, text/plain)
2003-09-21 02:58 UTC, Justin Heesemann
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Justin Heesemann 2003-09-17 04:58:16 UTC
This adds a new ebuild for the lsh implementation of ssh version 2 protocol.
lsh can be seen as a replacement for openssh and is said to be more secure (less
bugs? :)

Reproducible: Always
Steps to Reproduce:
Comment 1 Justin Heesemann 2003-09-17 04:59:16 UTC
Created attachment 17879 [details]
lsh-1.4.2.ebuild
Comment 2 Justin Heesemann 2003-09-17 04:59:38 UTC
Created attachment 17880 [details]
lsh-1.4.2.ebuild
Comment 3 Justin Heesemann 2003-09-17 05:01:20 UTC
Created attachment 17881 [details]
lsh-1.4.2.ebuild
Comment 4 Justin Heesemann 2003-09-17 05:02:48 UTC
(somehow i always get an error message, when i try to upload an attachment.. 
yet it seems like the attachment gets uploaded just fine) 
Comment 5 Justin Heesemann 2003-09-17 05:03:41 UTC
Created attachment 17883 [details]
init script
Comment 6 Justin Heesemann 2003-09-17 05:04:13 UTC
Created attachment 17884 [details]
/etc/conf.d/lshd
Comment 7 Jason Clinton 2003-09-17 07:44:55 UTC
In light of yesterdays buffer exploit in OpenSSH, diversity is probably a good thing. Note that a previous submission of this ebuild was rejected a year and a half ago. Please accept this ebuild, this time.
Comment 8 SpanKY gentoo-dev 2003-09-19 05:21:50 UTC
------- Additional Comments From arutha@gmx.de  2003-18-09 09:36 EST -------
Well I guess I gotta post this "I'm interested" comment now that I said so on 
gentoo-dev :) 
Comment 9 Patrick Lauer gentoo-dev 2003-09-19 08:35:09 UTC
There seems to be an exploit for lsh in the wild ...

http://www.heise.de/security/news/meldung/40434

http://lists.lysator.liu.se/pipermail/lsh-bugs/2003q3/000120.html

please do not commit 1.4.2 until these problems are resolved!
Comment 10 Justin Heesemann 2003-09-21 02:58:23 UTC
Created attachment 18066 [details]
version 1.4.3 fixes security problem

no changes to the 1.4.2-ebuild, just a newer version of lsh.
since 1.4.2 has an remote root exploit, and this new version fixes the bug..
emerge the new one.
Comment 11 SpanKY gentoo-dev 2003-10-28 10:39:32 UTC
now in cvs ... i disabled kerberos support since (1) it didnt compile for
me and (2) i didnt really feel like messing around with it ;)
Comment 12 Rainer Größlinger (RETIRED) gentoo-dev 2004-07-11 04:17:55 UTC
Hi, the lsh package is a bit broken, see bug #56156.
This effectively prevents other packages depending on the nettle library to go into portage.

Since I have no experience with lsh and don't want to decrease the quality even more, I don't feel like fixing it ;)