[ubuntu/noble-security] python-asyncssh 2.10.1-2ubuntu0.1 (Accepted)

Alex Murray alex.murray at canonical.com
Wed Oct 2 05:21:44 UTC 2024


python-asyncssh (2.10.1-2ubuntu0.1) noble-security; urgency=medium

  [Nishit Majithia]
  * Fix FTBFS due to unit test cases failures
    - d/p/fix-test_home_percent_expansion_unavailable.patch: Avoid using
      internal members of Path
    - d/p/fix-sha1-tests.patch: Handle elimination of SHA-1 for digital
      signatures in cryptograhy 39.0.0
    - d/p/fix-fido2_related_tests.patch: Increase minimum required fido2
      version to 0.9.2
    - d/p/fix-test_stdout_stream.patch: Read from stdout instead of
      communicate

  [Shishir Subedi]
  * SECURITY UPDATE: Prefix truncation attack on BPP
    - debian/patches/CVE-2023-48795.patch: implement "strict key exchange"
      in connection.py
    - CVE-2023-48795

Date: 2024-10-01 06:08:25.038395+00:00
Changed-By: Shishir Subedi <shishirsub10 at gmail.com>
Signed-By: Alex Murray <alex.murray at canonical.com>
https://launchpad.net/ubuntu/+source/python-asyncssh/2.10.1-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list