New Debian openssh 1:7.9p1-10+deb10u5 fixes: This update addresses the following issues: 1:7.9p1-10+deb10u5 (Wed, 19 Feb 2025 11:13:37 +0000) [ Santiago Ruano Rincón ] * Fix variables declaration in debian/salsa-ci.yml * Fix test cert not yet valid by using cert dates after the end of buster ELTS. Add debian/patches/test-fix-cert-not-yet-valid.patch * Import d/patches/CVE-2020-14145-partial-mitigation.patch to mitigate CVE-2020-14145. It is not a complete fix, and only helps in a specific case. [ Colin Watson ] * CVE-2025-26465: Fix MitM in verify_host_key_callback * Fix incorrect return values on a number of error paths * Pass on compiler/linker flags when building debian/keygen-test
--- mirror/ftp/pool/main/o/openssh/openssh_7.9p1-10+deb10u4.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/openssh_7.9p1-10+deb10u5.dsc @@ -1,3 +1,18 @@ +1:7.9p1-10+deb10u5 [Wed, 19 Feb 2025 11:13:37 +0000] Colin Watson <cjwatson@debian.org>: + + [ Santiago Ruano Rincón ] + * Fix variables declaration in debian/salsa-ci.yml + * Fix test cert not yet valid by using cert dates after the end of buster + ELTS. Add debian/patches/test-fix-cert-not-yet-valid.patch + * Import d/patches/CVE-2020-14145-partial-mitigation.patch to mitigate + CVE-2020-14145. It is not a complete fix, and only helps in a specific + case. + + [ Colin Watson ] + * CVE-2025-26465: Fix MitM in verify_host_key_callback + * Fix incorrect return values on a number of error paths + * Pass on compiler/linker flags when building debian/keygen-test + 1:7.9p1-10+deb10u4 [Sun, 24 Dec 2023 15:39:13 -0500] Santiago Ruano Rincón <santiago@freexian.com>: * Non-maintainer upload by the LTS Team. <http://piuparts.knut.univention.de/5.0-9/#7349273666238609391>
OK: piuparts OK: automated tests
<https://errata.software-univention.de/#/?erratum=5.0x1218>