Format: 1.8 Date: Tue, 02 Jan 2024 11:33:40 -0500 Source: openssh Binary: openssh-client openssh-server openssh-sftp-server openssh-tests ssh ssh-askpass-gnome Built-For-Profiles: noudeb Architecture: amd64 amd64_translations all Version: 1:9.3p1-1ubuntu3.2 Distribution: mantic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: openssh-client - secure shell (SSH) client, for secure access to remote machines openssh-server - secure shell (SSH) server, for secure access from remote machines openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot openssh-tests - OpenSSH regression tests ssh - secure shell client and server (metapackage) ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad Changes: openssh (1:9.3p1-1ubuntu3.2) mantic-security; urgency=medium . * SECURITY UPDATE: incomplete PKCS#11 destination constraints - debian/patches/CVE-2023-51384.patch: apply destination constraints to all p11 keys in ssh-agent.c. - CVE-2023-51384 * SECURITY UPDATE: command injection via shell metacharacters - debian/patches/CVE-2023-51385.patch: ban user/hostnames with most shell metacharacters in ssh.c. - CVE-2023-51385 Checksums-Sha1: 6a06d9a3ff0fbebf4517aac0474b54d22fd9dd08 3118124 openssh-client-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 015222b9555c0b83bc7dae2c6a6883852f01fb16 909734 openssh-client_9.3p1-1ubuntu3.2_amd64.deb 23aee0765665dbaf0dfaf79c5eb7909d3b991570 965582 openssh-server-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 44e47de3dce4d7b58d1cbc872e04ab2fc88f15d5 439788 openssh-server_9.3p1-1ubuntu3.2_amd64.deb 1c3bb721b4de13e2a54d1e2609e91381f9fb5c51 107840 openssh-sftp-server-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 1043617bf0f25f483ba5a4e2fe686104e74403fe 38740 openssh-sftp-server_9.3p1-1ubuntu3.2_amd64.deb ab16579482c9c20b9a6136c1b84aef1f0ca377f7 1630950 openssh-tests-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb a7fa8f5fee68823a58669251ad52eeabf8a410bb 1383624 openssh-tests_9.3p1-1ubuntu3.2_amd64.deb 03aa5fa8938c50411573469f0065d0e6e44ebf24 18545 openssh_9.3p1-1ubuntu3.2_amd64.buildinfo e2bd62f562bcee756e314636a8c1218a3245dbc7 9723 openssh_9.3p1-1ubuntu3.2_amd64_translations.tar.gz 52890bc12710b8170b1229fd167952d62d7178d6 17558 ssh-askpass-gnome-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 76d5132c272af9a2fca3a43d622e54a84d45149e 18512 ssh-askpass-gnome_9.3p1-1ubuntu3.2_amd64.deb 90e793541820ff81e68eb8e1a831be7f407f9fa3 4662 ssh_9.3p1-1ubuntu3.2_all.deb Checksums-Sha256: bf112d5af519080cbf256ed750baec7372a683ec156f6f50055bc4b2ac6c2317 3118124 openssh-client-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 3a8d3422078b9434d6bb3803be43a5d06fda94811ee024bea553ff9ddc5e0352 909734 openssh-client_9.3p1-1ubuntu3.2_amd64.deb 6fd7044956e66442a28e37590cd738af36b983cb3948e1f59d717a106325ef0f 965582 openssh-server-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb b66898ef03109faf2091bcdb2d80137e6fa12f1ed126f62487cd59680f3d49ee 439788 openssh-server_9.3p1-1ubuntu3.2_amd64.deb 254613da83abae942dbcb37eec30675d5096061d0b84535a7d8d501b89297bc2 107840 openssh-sftp-server-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 1be7d618e7d61e45311468ece918a2e9877fd71485abfb002c5653bed1e476d1 38740 openssh-sftp-server_9.3p1-1ubuntu3.2_amd64.deb 5707c8573ae0c4086d7539c49694f3a1e5ac61c6b392c5b3606504432bec3fd0 1630950 openssh-tests-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 53a1d837cfcef0cd7cd8b6721de2135996499afd24408266d4494d671fd5549d 1383624 openssh-tests_9.3p1-1ubuntu3.2_amd64.deb e30bd338fe7ab3c0c6e992d260389562aa2090f00c5e3461b99328e8dabf9e06 18545 openssh_9.3p1-1ubuntu3.2_amd64.buildinfo 16fe1d743f61b84a79a23817e234d3c916a7de648f87f70b9995f7cb2ddf9a2f 9723 openssh_9.3p1-1ubuntu3.2_amd64_translations.tar.gz 4e430755e5acbc18db4e2af87bed5ba5217c473aa147de8503daced947ebfc33 17558 ssh-askpass-gnome-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 051a601d26ecf5d4b32ee58bba91fa946ab5e1f48e43d0eecbf2723fb7868f80 18512 ssh-askpass-gnome_9.3p1-1ubuntu3.2_amd64.deb fb6c96fdf5fc14760dc782c692ea43c1a0ebc7994d98045a612aa8b18970d0c8 4662 ssh_9.3p1-1ubuntu3.2_all.deb Files: c63de1f4eac17fd49c388c43cfa8d9a5 3118124 debug optional openssh-client-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb db07f4e9731937ff4c963ce9cac6df4f 909734 net standard openssh-client_9.3p1-1ubuntu3.2_amd64.deb 220b69aa0ed421a33470417540cea255 965582 debug optional openssh-server-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb b363609bf861a31379916b08cbac0652 439788 net optional openssh-server_9.3p1-1ubuntu3.2_amd64.deb 5a4907179c12d7a826111b160ac5db94 107840 debug optional openssh-sftp-server-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb e8ce5eb26d937c52afacd6a40f7ccf4f 38740 net optional openssh-sftp-server_9.3p1-1ubuntu3.2_amd64.deb c63b841090677b87d02e02e291c5c752 1630950 debug optional openssh-tests-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb f382cf21b1dad84ecff032a5a6040893 1383624 net optional openssh-tests_9.3p1-1ubuntu3.2_amd64.deb 21898bb9544e6588d880274a7abfaaca 18545 net standard openssh_9.3p1-1ubuntu3.2_amd64.buildinfo 8953c6f44470d2a640b32cde7d019b80 9723 raw-translations - openssh_9.3p1-1ubuntu3.2_amd64_translations.tar.gz b69b3dec2569a755ef400fd5427fb3df 17558 debug optional ssh-askpass-gnome-dbgsym_9.3p1-1ubuntu3.2_amd64.ddeb 4a939105269ce63a080164e989d6cf66 18512 gnome optional ssh-askpass-gnome_9.3p1-1ubuntu3.2_amd64.deb 4c35c901fb2dc71f7bec603d1fa8e5b4 4662 net optional ssh_9.3p1-1ubuntu3.2_all.deb Original-Maintainer: Debian OpenSSH Maintainers