]> code.ossystems Code Review - openembedded-core.git/commit
dropbear: Fix CVE-2020-36254
authorErnst Sjöstrand <ernst.sjostrand@verisure.com>
Tue, 21 Dec 2021 17:24:01 +0000 (17:24 +0000)
committerSteve Sakoman <steve@sakoman.com>
Tue, 21 Dec 2021 17:39:56 +0000 (07:39 -1000)
commit10712b736d7cbde897c5aab30e969c04740dce34
treeec5a219b20c2ae017ec68309661cbf2faad5ffd7
parent22de3b937dda28a6aa4113549f32f36d67b6751d
dropbear: Fix CVE-2020-36254

Dropbear shares a lot of code with other SSH implementations, so this is
a port of CVE-2018-20685 to dropbear by the dropbear developers.

Reference:
https://github.com/mkj/dropbear/commit/8f8a3dff705fad774a10864a2e3dbcfa9779ceff

CVE: CVE-2020-36254
Upstream-Status: Backport

Signed-off-by: Ernst Sjöstrand <ernst.sjostrand@verisure.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/dropbear/dropbear.inc
meta/recipes-core/dropbear/dropbear/CVE-2020-36254.patch [new file with mode: 0644]