-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 28 Dec 2021 02:09:08 +0530 Source: paramiko Architecture: source Version: 2.0.0-1+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Jeremy T. Bouse <jbouse@debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Closes: 892859 910760 Changes: paramiko (2.0.0-1+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the LTS Team. * Fixes:CVE-2018-1000805; Closes: #910760. Fix to prevent malicious clients to trick the Paramiko server into thinking an unauthenticated client is authenticated. * Fixes: CVE-2018-7750; Closes: #892859. Fix check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step. Checksums-Sha1: 225cf6b1781068142b41b98f7558620f9902640f 2422 paramiko_2.0.0-1+deb9u1.dsc 6d6b30935eb49dba976fab62b8189b60e29aa817 273791 paramiko_2.0.0.orig.tar.gz 8848a9aec35f382318569f31bf22e556dcd23cf7 9244 paramiko_2.0.0-1+deb9u1.debian.tar.xz 4885df8e9824bd5585bb5748cf342527e2b663e6 6967 paramiko_2.0.0-1+deb9u1_source.buildinfo Checksums-Sha256: c66c4822a7af94f34208b5329b02015e6d79081aafd6740bfb675d3f3fccf0f0 2422 paramiko_2.0.0-1+deb9u1.dsc acf3866621794d68ce42bd5bcb769b6f9ff7e362cc1064e1b1af4185cdc4ed3b 273791 paramiko_2.0.0.orig.tar.gz 82e80730bb0f1d0555bcf228e12f347b356ef0cfb896fc7ca01211e0aa5022cf 9244 paramiko_2.0.0-1+deb9u1.debian.tar.xz 43230e506c4c93a1c98dd93a5dc7c8dca1cf6422b545d102b08ec756e09d53d1 6967 paramiko_2.0.0-1+deb9u1_source.buildinfo Files: cd94bafd42447fccc3e27d3f60b84bd0 2422 python optional paramiko_2.0.0-1+deb9u1.dsc 2fa5d3d4e1d6c79b2c2c99c237045649 273791 python optional paramiko_2.0.0.orig.tar.gz 66c840f4fd4bb4300f96dea276088ec5 9244 python optional paramiko_2.0.0-1+deb9u1.debian.tar.xz 97b33230a489592f9ab19ec8be680ded 6967 python optional paramiko_2.0.0-1+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmHK2VITHHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLlisgEACAw1ho3Hdu1hxPHpPdaGD8ykruHGzg yof/z14AwB6EJqf81lWx22RLf1ryXn3q9FRjb69v+QhMAUUN4CW0IIljEzwv5w+7 WHTu+GdGbiuq4/Fju+c+lBHBIK8158OAD/4+6oY/2sG5S3ikVKsWp1OKLB1HSK/2 x5o1M/urGxXHztX2gQK/6HwUnxmmazJDpeAYSQEEuTx0Ip56ia4+dH+xRm9bU82R PvDjr+6rTFFOMVsdp5oA0EtTreXJUSeXk/w8Uz7dMdykXfqLU+QaIpqt9M0XRorH H5IX+hi5bu/Bxr3nKMYG3qIVY64HN+PeP05mozz91IX28ENm2NQH6gZ0LzSQ7llg lh9/9iGwHcCLcHEQSebpZ/1P2MrFXQVMr907zKKiNOa9sxivZMCEmnPOGLGdhAQV 0r2I97Qz7CcnAw6oNFuTStmJiUwd5gM273iCa5TDWRS+kgeZ+vTdGrGVZY6sBGOe 0IfLMZx4Dh/xfP3c6N7J/e9xg0BbLhnDhWtLLC1kT4qg5+ubLpvvNuLWFdBw3wBm qUooCFPIYdSoOfYoj9BahvtPq/ZTwRPe+QsYUgrTyj4Yht3euxjW1ZTQwbYo9bY1 SzxxO8Vy7B3bCpppo++g3erIzb/l3Sq8yPN5Qxszg0C503nNVEveCgmXdizbTGUT SfJsOlFa6D8aJQ== =3kfq -----END PGP SIGNATURE-----