All of lore.kernel.org
 help / color / mirror / Atom feed
From: Thomas De Schampheleire <patrickdepinguin@gmail.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH] package/dropbear: bump to version 2020.79
Date: Tue, 4 Aug 2020 15:24:06 +0200	[thread overview]
Message-ID: <CAAXf6LU8EVnL9fKZnW07W+AW8w3Cz7qP_eFz_z_4mE3eUX5seQ@mail.gmail.com> (raw)
In-Reply-To: <87bljqskpj.fsf@dell.be.48ers.dk>

Hi Peter,

El mar., 4 ago. 2020 a las 13:40, Peter Korsgaard (<peter@korsgaard.com>)
escribi?:

> >>>>> "Thomas" == Thomas De Schampheleire <patrickdepinguin@gmail.com>
> writes:
>
>  > Hi Peter,
>  > El lun., 22 jun. 2020 a las 11:07, Peter Korsgaard (<
> peter at korsgaard.com>)
>  > escribi?:
>
>  >> >>>>> "Francois" == Francois Perrad <fperrad@gmail.com> writes:
>  >>
>  >> > CBC ciphers, 3DES and hmac-sha1-96 are now disabled by default.
>  >>
>  >> Do we expect that to cause compatibility issues?
>  >>
>  >> Committed, thanks.
>  >>
>
>
>  > I just want to notify you that this dropbear release 2020.79 also
> contains
>  > a security fix: (from the CHANGES file):
>
>  >          - scp fix for CVE-2018-20685 where a server could modify name
> of
>  > output files
>
>  > and as such this update (or the later one to update to 2020.80) should
> also
>  > be applied on the LTS branch.
>
> Ahh yes, true. 2020.79 does bring quite some new features / changes
> though, would a backport of the scp fix be feasible?
>

Seems it would, the fix is a simple patch that applies cleanly on top of
2019.78.
https://hg.ucc.asn.au/dropbear/changeset/3080aed32bf1

I can send a patch.

Best regards,
Thomas
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.busybox.net/pipermail/buildroot/attachments/20200804/c147c7ff/attachment.html>

      reply	other threads:[~2020-08-04 13:24 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-06-22  7:39 [Buildroot] [PATCH] package/dropbear: bump to version 2020.79 Francois Perrad
2020-06-22  9:07 ` Peter Korsgaard
2020-06-22 10:51   ` Alexander Dahl
2020-06-22 18:48     ` François Perrad
2020-06-23  6:24       ` Peter Korsgaard
2020-06-23  6:19     ` Peter Korsgaard
2020-08-04 10:15   ` Thomas De Schampheleire
2020-08-04 11:40     ` Peter Korsgaard
2020-08-04 13:24       ` Thomas De Schampheleire [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=CAAXf6LU8EVnL9fKZnW07W+AW8w3Cz7qP_eFz_z_4mE3eUX5seQ@mail.gmail.com \
    --to=patrickdepinguin@gmail.com \
    --cc=buildroot@busybox.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.