mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-06 07:34:01 -09:00
https://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1 https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ Fixes the following security problems: CVE-2026-15370: Stack buffer overflow in SFTP server longname construction CVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key CVE-2026-59843: Denial of service via zero advertised channel packet size CVE-2026-59844: Denial of service via oversized SFTP read length CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs CVE-2026-59849: Denial of service via automatic certificate authentication loop CVE-2026-59850: Use-after-free via data callbacks on closed channels CVE-2026-59851: Authentication bypass via missing GSSAPI principal check Zero-initialize every ssh_string Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr>
6 lines
340 B
Plaintext
6 lines
340 B
Plaintext
# Locally calculated after checking pgp signature
|
|
# https://www.libssh.org/files/0.12/libssh-0.12.1.tar.xz.asc
|
|
# with key 88A228D89B07C2C77D0C780903D5DF8CFDD3E8E7
|
|
sha256 d3941af0a2d78d5d82ed7a36988e9133994312f035b9659a6e43f8db3968784c libssh-0.12.1.tar.xz
|
|
sha256 1656186e951db1c010a8485481fa94587f7e53a26d24976bef97945ad0c4df5a COPYING
|