[ubuntu/oracular-proposed] openssh 1:9.6p1-3ubuntu16 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Jul 9 11:58:19 UTC 2024


openssh (1:9.6p1-3ubuntu16) oracular; urgency=medium

  * SECURITY UPDATE: timing attack against echo-off password entry
    - debian/patches/CVE-2024-39894.patch: don't rely on
      channel_did_enqueue in clientloop.c
    - CVE-2024-39894

Date: Tue, 09 Jul 2024 07:28:38 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu16
-------------- next part --------------
Format: 1.8
Date: Tue, 09 Jul 2024 07:28:38 -0400
Source: openssh
Built-For-Profiles: noudeb
Architecture: source
Version: 1:9.6p1-3ubuntu16
Distribution: oracular
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 openssh (1:9.6p1-3ubuntu16) oracular; urgency=medium
 .
   * SECURITY UPDATE: timing attack against echo-off password entry
     - debian/patches/CVE-2024-39894.patch: don't rely on
       channel_did_enqueue in clientloop.c
     - CVE-2024-39894
Checksums-Sha1:
 33332645db27f05993776a5868cbade0bbef7332 3334 openssh_9.6p1-3ubuntu16.dsc
 bfeaa6cab0593683e4aa80afaf6396ab2dc5eb94 204264 openssh_9.6p1-3ubuntu16.debian.tar.xz
 67beb9bc399ea0808929c70f6228a4cd07617859 16693 openssh_9.6p1-3ubuntu16_source.buildinfo
Checksums-Sha256:
 fee765f77114931ec72ae37e4eceeb00e57045a3a886eeb5beb1ba712a9014cb 3334 openssh_9.6p1-3ubuntu16.dsc
 4c68a0969213ac6506975d21467f1608f3b937aee216bbab526c4269092fc6aa 204264 openssh_9.6p1-3ubuntu16.debian.tar.xz
 de2671a70be725daaf05483ada7f99cd92c71d24c7d087144099a85a773b2f14 16693 openssh_9.6p1-3ubuntu16_source.buildinfo
Files:
 15eab15062127964cff7dc3778f0e919 3334 net standard openssh_9.6p1-3ubuntu16.dsc
 364aa20bac8eb9f2feec23ba61d9ffcb 204264 net standard openssh_9.6p1-3ubuntu16.debian.tar.xz
 e962cf81f8e1628fe50d8a0c00631869 16693 net standard openssh_9.6p1-3ubuntu16_source.buildinfo
Original-Maintainer: Debian OpenSSH Maintainers <debian-ssh at lists.debian.org>


More information about the oracular-changes mailing list