Overview
Request 1134431 superseded
- Update to version 0.10.6
https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/
- Fix CVE-2023-6004: ProxyCommand/ProxyJump features allow injection of malicious code through hostname (bsc#1218209)
- Fix CVE-2023-48795: prefix truncation breaking ssh channel integrity (bsc#1218126)
- Fix CVE-2023-6918: Added Missing checks for return values for digests (bsc#1218186)
- Created by adamm
- In state superseded
- Supersedes 1134048
- Superseded by 1134726
- Open review for factory-staging
This update is beaking cockpit, see https://build.opensuse.org/package/live_build_log/openSUSE:Factory:Staging:M/cockpit/standard/x86_64
Request History
adamm created request
- Update to version 0.10.6
https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/
- Fix CVE-2023-6004: ProxyCommand/ProxyJump features allow injection of malicious code through hostname (bsc#1218209)
- Fix CVE-2023-48795: prefix truncation breaking ssh channel integrity (bsc#1218126)
- Fix CVE-2023-6918: Added Missing checks for return values for digests (bsc#1218186)
factory-auto added opensuse-review-team as a reviewer
Please review sources
factory-auto accepted review
Check script succeeded
licensedigger accepted review
ok
anag+factory set openSUSE:Factory:Staging:M as a staging project
Being evaluated by staging project "openSUSE:Factory:Staging:M"
anag+factory accepted review
Picked "openSUSE:Factory:Staging:M"
oertel accepted review
Accepted review for by_group opensuse-review-team request 1134431 from user anag+factory
anag+factory added factory-staging as a reviewer
Being evaluated by group "factory-staging"
anag+factory accepted review
Unstaged from project "openSUSE:Factory:Staging:M"
FTR, the FTBFS with cockpit is still present
breaks cockpit, it's a security update!
See https://gitlab.com/libssh/libssh-mirror/-/issues/227
FWIW the short message is automatically added when updating the exclude list:
https://build.opensuse.org/staging_workflows/openSUSE:Factory/excluded_requests