-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 02 Feb 2024 23:49:12 +0100 Source: dropbear Architecture: source Version: 2022.83-1+deb12u1~bpo11+1 Distribution: bullseye-backports Urgency: medium Maintainer: Guilhem Moulin <guilhem@debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1059001 Changes: dropbear (2022.83-1+deb12u1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. * Add d/salsa-ci.yml for Salsa CI. . dropbear (2022.83-1+deb12u1) bookworm; urgency=medium . * Fix CVE-2023-48795: (terrapin attack): The SSH transport protocol with certain OpenSSH extensions allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. (Closes: #1059001) Checksums-Sha1: 6166a9e47d1f950fdc5db381a15f58dbb2452967 2646 dropbear_2022.83-1+deb12u1~bpo11+1.dsc 57b15a9a6f2865391f3bc3f333b65c701cdaf73f 37064 dropbear_2022.83-1+deb12u1~bpo11+1.debian.tar.xz da4b03cc26c54535baa9704ba119cb99a26e407b 7600 dropbear_2022.83-1+deb12u1~bpo11+1_amd64.buildinfo Checksums-Sha256: fa8d385cf531b8e496883fea82270cdc34b3bdfedf3729f11b66008d2938b783 2646 dropbear_2022.83-1+deb12u1~bpo11+1.dsc 7ef618fb8d821bc2642294a236d4ec46c6530a2683978c03f7e46984e485ffbe 37064 dropbear_2022.83-1+deb12u1~bpo11+1.debian.tar.xz 4bf23ff2c1dbf09b5a898acb0d242049b4bc2dbc783d999c59d9476d6e2bd256 7600 dropbear_2022.83-1+deb12u1~bpo11+1_amd64.buildinfo Files: 1800b6bf1dac8ec447b7cac51c7b25b9 2646 net optional dropbear_2022.83-1+deb12u1~bpo11+1.dsc 3888a010aec12a31a35773fef3ec38d7 37064 net optional dropbear_2022.83-1+deb12u1~bpo11+1.debian.tar.xz 8353c5171e71613f21869f711475f6d6 7600 net optional dropbear_2022.83-1+deb12u1~bpo11+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmW9crIACgkQ05pJnDwh pVLSHw//YCcCadh5FlXt8vWLd2v/8YQhZqTmmPi8+jk11qY2M/uEuV3gTdt8zxcT Fu705zlOTETK8k84O63CdG5782sHHY/dWYlPZEQ2/lM5hVdSaZWeBFfWexdUj6Pl R7lLe19sTQ14vgYU4Lpr0JfCn5thuk0sxX5SNtwoCtNEsQ9goFvRFV7GBekyqikc gYWMF7QV9r9naKi5tXtTtg3ZpotOkl63xN6S1wLt0mHmDJGIfApEHGUoPKpwgUMP kE+bG6/t9xtLCpw7LEqSiiCz4zqzX44elVe5ScblBgzDVKpHwKgrgOW/RJSzf5CW 8WbRasdcuwf29epBUP+OoukCiFsGPMXK+1w+ZEdrwaTI+I+dVPOmktaKUohXFgbX pMyStVST2G4bUTG9cvfDXS8XgbYkl+uFF9a6IcVVEQoQM3+1bKGayMmoNBAJvr5P Qdf7B1stbASW6Z4SoAZ6Z8A6nWI84w3jrL+5aiMpR7l+v5rgyFxsNaD5PHCRgpcz TGck8G6UReduKO6OU6GVrO63Zm8zDVx2ey18HLJ1dncw7+RykPsfQL+mJVkALUq9 tOVidrGPMVCv5zNKufIHKBENgUgPXGgukLTgN/NeAARu9X6ucZyIBIcyLmluNlHk IQU3pwIYXlujTmN2jM4qIZGFl+8HBLqo/loTLk1Q9ufEv8PUph0= =gQ2k -----END PGP SIGNATURE-----