]> code.ossystems Code Review - openembedded-core.git/commit
openssh: fix for CVE-2014-2532
authorChen Qi <Qi.Chen@windriver.com>
Tue, 13 May 2014 07:46:26 +0000 (15:46 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 13 May 2014 18:26:34 +0000 (19:26 +0100)
commita8d3b8979c27a8dc87971b66a1d9d9282f660596
tree86068a8446be1c4908e3c6b11dc08692944fbcf3
parentecb819b12a89e4e944974068d2e20ed226979317
openssh: fix for CVE-2014-2532

sshd in OpenSSH before 6.6 does not properly support wildcards on
AcceptEnv lines in sshd_config, which allows remote attackers to
bypass intended environment restrictions by using a substring located
before a wildcard character.

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-connectivity/openssh/openssh/openssh-CVE-2014-2532.patch [new file with mode: 0644]
meta/recipes-connectivity/openssh/openssh_6.5p1.bb