[ubuntu/hirsute-proposed] openssh 1:8.4p1-4ubuntu2 (Accepted)
Marc Deslauriers
marc.deslauriers at ubuntu.com
Tue Mar 9 16:35:13 UTC 2021
openssh (1:8.4p1-4ubuntu2) hirsute; urgency=medium
* SECURITY UPDATE: double-free memory corruption in ssh-agent
- debian/patches/CVE-2021-28041.patch: set ext_name to NULL after
freeing it so it doesn't get freed again later on in ssh-agent.c.
- CVE-2021-28041
Date: Tue, 09 Mar 2021 08:44:15 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/openssh/1:8.4p1-4ubuntu2
-------------- next part --------------
Format: 1.8
Date: Tue, 09 Mar 2021 08:44:15 -0500
Source: openssh
Built-For-Profiles: noudeb
Architecture: source
Version: 1:8.4p1-4ubuntu2
Distribution: hirsute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
openssh (1:8.4p1-4ubuntu2) hirsute; urgency=medium
.
* SECURITY UPDATE: double-free memory corruption in ssh-agent
- debian/patches/CVE-2021-28041.patch: set ext_name to NULL after
freeing it so it doesn't get freed again later on in ssh-agent.c.
- CVE-2021-28041
Checksums-Sha1:
221094514355b227640a9c96029248dbe7ef7cf4 3345 openssh_8.4p1-4ubuntu2.dsc
4c7d9b1217bfd15daf2089ca432177b9e34d0044 179860 openssh_8.4p1-4ubuntu2.debian.tar.xz
a4e26a312e0dc47f20de56740b22d1609ceb5353 16004 openssh_8.4p1-4ubuntu2_source.buildinfo
Checksums-Sha256:
e3d9d44dfc428c77ec8d262ec2b14544919d0f66989b68f635cc9b16b00c8b0c 3345 openssh_8.4p1-4ubuntu2.dsc
44de47dbd4fda2e72bef7a326f29e968531877bfaa6607eca568f4c936722683 179860 openssh_8.4p1-4ubuntu2.debian.tar.xz
db58d2e7b590de3ac6c11cf9df6dedd1aeab277e1aee2de8b10f5280f0f35106 16004 openssh_8.4p1-4ubuntu2_source.buildinfo
Files:
1152eb1c849f03ea8951470712ae5906 3345 net standard openssh_8.4p1-4ubuntu2.dsc
68550c507c6ac2ec8e084afd938a3605 179860 net standard openssh_8.4p1-4ubuntu2.debian.tar.xz
f367e37b0b163bb8a0a3e36796c5d3b7 16004 net standard openssh_8.4p1-4ubuntu2_source.buildinfo
Original-Maintainer: Debian OpenSSH Maintainers <debian-ssh at lists.debian.org>
More information about the Hirsute-changes
mailing list