| Summary: | OpenSSH client: CVE-2016-0777, CVE-2016-0778 and CVE-2016-1907 | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Armin Kuster <akuster> |
| Component: | core | Assignee: | Armin Kuster <akuster> |
| Status: | VERIFIED FIXED | QA Contact: | Alexandru Roman <alexandru.costinx.roman> |
| Severity: | normal | ||
| Priority: | High | CC: | bogdanx.a.voiculescu, joshuagloe, meta.mr.watcher, meta.watcher |
| Version: | 2.0.1 | ||
| Target Milestone: | 2.0.2 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Armin Kuster
2016-01-15 18:47:25 UTC
Master package was updated to 7.1p2 http://cgit.openembedded.org/openembedded-core/commit/?id=b3b679d5be86f73d1a06c7230cb00872f0a407b5 Jethro is at version 7.1.p1 so cherry-picking this should be ok. Fido needs patches.. working on them. new on logged this morning.
Master is affect
> SECURITY: Fix an out of-bound read access in the packet handling code.
> Reported by Ben Hawkes
> https://anongit.mindrot.org/openssh.git/commit/?id=2fecfd486bdba9f51b3a789277bb0733ca36e1c0
Use CVE-2016-1907.
unfortunate I am getting fetch errors. ERROR: Function failed: Fetcher failure for URL: 'ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-7.1p2.tar.gz'. Unable to fetch URL from any source. ERROR: Logfile of failure stored in: /yocto/OE/maint/poky/build/tmp/work/core2-64-poky-linux/openssh/7.1p2-r0/temp/log.do_fetch.5930 ERROR: Task 5 (/yocto/OE/maint/poky/meta/recipes-connectivity/openssh/openssh_7.1p2.bb, do_fetch) failed with exit code '1' the tarball does not exists on openbsd nor any of its mirrors. maybe too soon. CVE-2016-1907: Master and Jethro patch sent http://patches.openembedded.org/patch/112553/ Jethro was just updated for CVE-2016-0777 and CVE-2016-0778 by package update. shoot. need two more commits for 2016-1907... https://anongit.mindrot.org/openssh.git/commit/?id=f98a09cacff7baad8748c9aa217afd155a4d493f https://anongit.mindrot.org/openssh.git/commit/?id=ed4ce82dbfa8a3a3c8ea6fa0db113c71e234416c new master and Jethro patch series sent. http://patches.openembedded.org/patch/112555/ fido updated for CVE-2016-077x http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?h=fido&id=9845a542a76156adb5aef6fd33ad5bc5777acf64 Verified. |