Path to this page:
Subject: CVS commit: pkgsrc/security/libssh
From: Thomas Klausner
Date: 2023-12-18 18:07:25
Message id: 20231218170725.47BD4FA42@cvs.NetBSD.org
Log Message:
libssh: update to 0.106.
version 0.10.6 (released 2023-12-18)
* Fix CVE-2023-6004: Command injection using proxycommand
* Fix CVE-2023-48795: Potential downgrade attack using strict kex
* Fix CVE-2023-6918: Missing checks for return values of MD functions
* Fix ssh_send_issue_banner() for CMD(PowerShell)
* Avoid passing other events to callbacks when poll is called recursively (#202)
* Allow @ in usernames when parsing from URI composes
Files: