Debian Package Tracker
Register | Log in
Subscribe

dropbear

lightweight SSH2 server and client - startup scripts

Choose email to subscribe with

general
  • source: dropbear (main)
  • version: 2022.83-1
  • maintainer: Guilhem Moulin (DMD)
  • arch: all any
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2016.74-5+deb9u1
  • oldstable: 2018.76-5+deb10u1
  • old-sec: 2018.76-5+deb10u2
  • stable: 2020.81-3
  • stable-bpo: 2022.83-1~bpo11+1
  • testing: 2022.83-1
  • unstable: 2022.83-1
versioned links
  • 2016.74-5+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2018.76-5+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2018.76-5+deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2020.81-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2022.83-1~bpo11+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2022.83-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • dropbear
  • dropbear-bin (1 bugs: 0, 0, 1, 0)
  • dropbear-initramfs (1 bugs: 0, 1, 0, 0)
  • dropbear-run
action needed
Debci reports failed tests high
  • unstable: pass (log)
    The tests ran in 0:11:05
    Last run: 2023-03-17T14:38:50.000Z
    Previous status: pass

  • testing: pass (log)
    The tests ran in 0:03:47
    Last run: 2023-03-16T12:27:56.000Z
    Previous status: pass

  • stable: fail (log)
    The tests ran in 0:05:11
    Last run: 2023-03-21T14:04:26.000Z
    Previous status: fail

Created: 2021-09-22 Last update: 2023-03-30 12:05
lintian reports 1 error high
Lintian reports 1 error about this package. You should make the package lintian clean getting rid of them.
Created: 2023-02-05 Last update: 2023-02-05 08:32
3 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 676336a452b76792983179471366a22f669711c6
Author: Guilhem Moulin <guilhem@debian.org>
Date:   Tue Dec 20 16:38:45 2022 +0100

    Update standards version to 4.6.2, no changes needed.
    
    Changes-By: lintian-brush
    Fixes: lintian: out-of-date-standards-version
    See-also: https://lintian.debian.org/tags/out-of-date-standards-version.html

commit 6c901bc4387b80882f7d7fbc1a96f1194509e1f2
Author: Guilhem Moulin <guilhem@debian.org>
Date:   Sun Nov 20 12:59:15 2022 +0100

    Add d/salsa-ci.yml.
    
    We need a custom CI/CD configuration file for backports (see 92532635ac5327781cc36f7bb9361cd556dbf230)
    and as this is a per-repo setting we define a (default) one for unstable
    as well.

commit 2bcbd755f438595a304a1ec02068ca12593bb2fa
Author: Guilhem Moulin <guilhem@debian.org>
Date:   Sat Nov 19 23:09:29 2022 +0100

    d/.gitattribute: New file for proper merging of d/chagelog.
Created: 2022-11-20 Last update: 2023-03-25 06:06
1 low-priority security issue in bullseye low

There is 1 open security issue in bullseye.

1 issue left for the package maintainer to handle:
  • CVE-2021-36369: (needs triaging) An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.

You can find information about how to handle this issue in the security team's documentation.

Created: 2022-10-21 Last update: 2023-03-27 11:06
debian/patches: 1 patch to forward upstream low

Among the 3 debian patches available in version 2022.83-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-12-17 Last update: 2022-12-17 19:18
news
[rss feed]
  • [2022-11-19] Accepted dropbear 2022.83-1~bpo11+1 (source) into bullseye-backports (Guilhem Moulin)
  • [2022-11-18] dropbear 2022.83-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-14] Accepted dropbear 2022.83-1 (source) into unstable (Guilhem Moulin)
  • [2022-10-28] Accepted dropbear 2018.76-5+deb10u2 (source) into oldstable (Utkarsh Gupta)
  • [2022-10-24] Accepted dropbear 2022.82-4.1~bpo11+1 (source amd64 all) into bullseye-backports (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2022-10-17] dropbear 2022.82-4.1 MIGRATED to testing (Debian testing watch)
  • [2022-10-15] Accepted dropbear 2022.82-4.1 (source) into unstable (Michael Biebl)
  • [2022-10-08] dropbear 2022.82-4 MIGRATED to testing (Debian testing watch)
  • [2022-10-05] Accepted dropbear 2022.82-4 (source) into unstable (Guilhem Moulin)
  • [2022-08-06] Accepted dropbear 2018.76-5+deb10u1 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2022-04-12] dropbear 2022.82-3 MIGRATED to testing (Debian testing watch)
  • [2022-04-05] dropbear 2022.82-2 MIGRATED to testing (Debian testing watch)
  • [2022-04-04] Accepted dropbear 2022.82-3 (source) into unstable (Guilhem Moulin)
  • [2022-04-03] Accepted dropbear 2022.82-2 (source) into unstable (Guilhem Moulin)
  • [2022-04-02] Accepted dropbear 2022.82-1 (source) into unstable (Guilhem Moulin)
  • [2021-12-13] dropbear 2020.81-5 MIGRATED to testing (Debian testing watch)
  • [2021-12-08] Accepted dropbear 2020.81-5 (source) into unstable (Guilhem Moulin)
  • [2021-08-29] dropbear 2020.81-4 MIGRATED to testing (Debian testing watch)
  • [2021-08-19] Accepted dropbear 2020.81-4 (source) into unstable (Guilhem Moulin)
  • [2021-01-17] dropbear 2020.81-3 MIGRATED to testing (Debian testing watch)
  • [2021-01-14] Accepted dropbear 2020.81-3 (source) into unstable (Guilhem Moulin)
  • [2021-01-04] dropbear 2020.81-2 MIGRATED to testing (Debian testing watch)
  • [2021-01-04] dropbear 2020.81-2 MIGRATED to testing (Debian testing watch)
  • [2021-01-01] Accepted dropbear 2020.81-2 (source) into unstable (Guilhem Moulin)
  • [2020-11-04] dropbear 2020.81-1 MIGRATED to testing (Debian testing watch)
  • [2020-10-29] Accepted dropbear 2020.81-1 (source) into unstable (Guilhem Moulin)
  • [2020-07-01] dropbear 2020.80-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-26] Accepted dropbear 2020.80-1 (source) into unstable (Guilhem Moulin)
  • [2020-06-19] dropbear 2020.79-2 MIGRATED to testing (Debian testing watch)
  • [2020-06-16] Accepted dropbear 2020.79-2 (source) into unstable (Guilhem Moulin)
  • 1
  • 2
bugs [bug history graph]
  • all: 4
  • RC: 0
  • I&N: 2
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (1, 0)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2022.83-1
  • 19 bugs (2 patches)

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing