CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
Master package was updated to 7.1p2 http://cgit.openembedded.org/openembedded-core/commit/?id=b3b679d5be86f73d1a06c7230cb00872f0a407b5 Jethro is at version 7.1.p1 so cherry-picking this should be ok. Fido needs patches.. working on them.
new on logged this morning. Master is affect > SECURITY: Fix an out of-bound read access in the packet handling code. > Reported by Ben Hawkes > https://anongit.mindrot.org/openssh.git/commit/?id=2fecfd486bdba9f51b3a789277bb0733ca36e1c0 Use CVE-2016-1907.
unfortunate I am getting fetch errors. ERROR: Function failed: Fetcher failure for URL: 'ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-7.1p2.tar.gz'. Unable to fetch URL from any source. ERROR: Logfile of failure stored in: /yocto/OE/maint/poky/build/tmp/work/core2-64-poky-linux/openssh/7.1p2-r0/temp/log.do_fetch.5930 ERROR: Task 5 (/yocto/OE/maint/poky/meta/recipes-connectivity/openssh/openssh_7.1p2.bb, do_fetch) failed with exit code '1' the tarball does not exists on openbsd nor any of its mirrors. maybe too soon.
CVE-2016-1907: Master and Jethro patch sent http://patches.openembedded.org/patch/112553/ Jethro was just updated for CVE-2016-0777 and CVE-2016-0778 by package update.
shoot. need two more commits for 2016-1907... https://anongit.mindrot.org/openssh.git/commit/?id=f98a09cacff7baad8748c9aa217afd155a4d493f https://anongit.mindrot.org/openssh.git/commit/?id=ed4ce82dbfa8a3a3c8ea6fa0db113c71e234416c
new master and Jethro patch series sent. http://patches.openembedded.org/patch/112555/
fido updated for CVE-2016-077x http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?h=fido&id=9845a542a76156adb5aef6fd33ad5bc5777acf64
Verified.