Format: 1.8 Date: Tue, 02 Jan 2024 11:33:40 -0500 Source: openssh Binary: openssh-client openssh-server openssh-sftp-server openssh-tests ssh-askpass-gnome Built-For-Profiles: noudeb Architecture: arm64 arm64_translations Version: 1:9.3p1-1ubuntu3.2 Distribution: mantic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: openssh-client - secure shell (SSH) client, for secure access to remote machines openssh-server - secure shell (SSH) server, for secure access from remote machines openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot openssh-tests - OpenSSH regression tests ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad Changes: openssh (1:9.3p1-1ubuntu3.2) mantic-security; urgency=medium . * SECURITY UPDATE: incomplete PKCS#11 destination constraints - debian/patches/CVE-2023-51384.patch: apply destination constraints to all p11 keys in ssh-agent.c. - CVE-2023-51384 * SECURITY UPDATE: command injection via shell metacharacters - debian/patches/CVE-2023-51385.patch: ban user/hostnames with most shell metacharacters in ssh.c. - CVE-2023-51385 Checksums-Sha1: f789aeea05004b2e4e1abd910d2f037b7bd37881 3076144 openssh-client-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 1cdbb0fa530cf50997b071d6987654ef4a030708 867844 openssh-client_9.3p1-1ubuntu3.2_arm64.deb 208aaeae46c2038e50491a611521662b44a91eff 960910 openssh-server-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 280affd3c3058d356da1cc729327a9311319170a 417550 openssh-server_9.3p1-1ubuntu3.2_arm64.deb d2d3ab2e6a27806d3c61ded61bb48af0c065e008 108976 openssh-sftp-server-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 490ada7ef2bc4022dd5f4e75baea822929b32de8 36596 openssh-sftp-server_9.3p1-1ubuntu3.2_arm64.deb 31825eb76482a9227e4235d7082c2e5c8734ee19 1614626 openssh-tests-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 3fcb569053d2e971618da1dc599aea731eeb8255 1373704 openssh-tests_9.3p1-1ubuntu3.2_arm64.deb 8fbda98791128f24f5e2d57d45eea4362f8723bf 18202 openssh_9.3p1-1ubuntu3.2_arm64.buildinfo a1a9b667b948372e9ad696a22fc7951d1956edee 9786 openssh_9.3p1-1ubuntu3.2_arm64_translations.tar.gz aca38ffb3897d5a136f4a768031056d9a76782ce 17444 ssh-askpass-gnome-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 647db2e912ff2ebac21841b95026c8c54be68361 17874 ssh-askpass-gnome_9.3p1-1ubuntu3.2_arm64.deb Checksums-Sha256: 532666c3cfa230aaf71a6dece3d4242e6c12522cb1cd8bb08150a0a30b2fbed2 3076144 openssh-client-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb d9e3da437140d4a4edb61dbdf31521aaf7c81e60da26dbbbfb2fe671ce1f4e32 867844 openssh-client_9.3p1-1ubuntu3.2_arm64.deb abe577717fcc687db2c442e9f8f6b0535e60fc3284a7320e55b2478094105421 960910 openssh-server-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 84f754a89f2cdcdd52f89793157008c08411ae16d434e5afd2efa3e1f2e40244 417550 openssh-server_9.3p1-1ubuntu3.2_arm64.deb e5da7d95f71c9dd8367aaa73be56800e76e855ff56b4a535bcfa359e07890edc 108976 openssh-sftp-server-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 85a77a1a19e8567faecf01b1448e9cfd4054f16f9a0c75c6cbd512537ede784f 36596 openssh-sftp-server_9.3p1-1ubuntu3.2_arm64.deb 36273d811356e2461be5d2db972e73352260ce7c754898a4103153c5ec8b186b 1614626 openssh-tests-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 26912c988e7c7bf1abf3ea05582a1ef54f8d612c8576d708518b916a2a52c880 1373704 openssh-tests_9.3p1-1ubuntu3.2_arm64.deb 4a37e1cebba707d6e2efa7c420ee070f9f642c37f39654873a1ba14d50dc1735 18202 openssh_9.3p1-1ubuntu3.2_arm64.buildinfo dbfade3de6b88c3f8521ae65182ecbd5d177f8a5ca606098264c91e6f7266204 9786 openssh_9.3p1-1ubuntu3.2_arm64_translations.tar.gz 3b7b10eb53a067787ccc9de284f15c970c735dc2a36371c902e0923c6f3cadcd 17444 ssh-askpass-gnome-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 8dca7038594c34d111e3b858a8a548f8caafe67e72059c61790bef535783786e 17874 ssh-askpass-gnome_9.3p1-1ubuntu3.2_arm64.deb Files: 60589c908f0dee5f05597dca1621eafc 3076144 debug optional openssh-client-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 055edc711e137bba3f597b384e496d9f 867844 net standard openssh-client_9.3p1-1ubuntu3.2_arm64.deb 2c7beb8e0e354df1acf884c1488435e5 960910 debug optional openssh-server-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 4a65222670d35043dec67ef487da4f83 417550 net optional openssh-server_9.3p1-1ubuntu3.2_arm64.deb bf1d0e246b10191dba92030d86b110a5 108976 debug optional openssh-sftp-server-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 3ef65a78ea157d333f804bc4538c8da3 36596 net optional openssh-sftp-server_9.3p1-1ubuntu3.2_arm64.deb ffdc55da501caaae0d08256c6bd4e7a0 1614626 debug optional openssh-tests-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb 5602c48fb130c96c8643a8ca4b3a4253 1373704 net optional openssh-tests_9.3p1-1ubuntu3.2_arm64.deb 84857cb59c783e7f806b48d94c53346d 18202 net standard openssh_9.3p1-1ubuntu3.2_arm64.buildinfo 53f8c0a99f4beec20df68d58c5aed94b 9786 raw-translations - openssh_9.3p1-1ubuntu3.2_arm64_translations.tar.gz c11c0c08f6fb7aa7732da95e9751b9bc 17444 debug optional ssh-askpass-gnome-dbgsym_9.3p1-1ubuntu3.2_arm64.ddeb e63cbb4b5c08676cf2f511cba4baccd4 17874 gnome optional ssh-askpass-gnome_9.3p1-1ubuntu3.2_arm64.deb Original-Maintainer: Debian OpenSSH Maintainers