红联Linux门户
Linux帮助

OpenSSH 6.6发布

发布时间:2014-03-17 10:47:10来源:红联作者:empast
OpenSSH(Open Secure Shell)是使用SSH透过计算机网络加密通讯的实现。它是取代由SSH Communications Security所提供的商用版本的开放源代码方案。目前OpenSSH是OpenBSD的子计划。

远程登录工具OpenSSH 6.6正式版发布。2014-03-16 上个版本是2014-01-30的6.5 修正了一些Bug及几个增强,去掉J-PAKE认证。

完全改进:

Changes since OpenSSH 6.6
=========================

This is primarily a bugfix release.

Security:

* sshd(8): when using environment passing with a sshd_config(5)
AcceptEnv pattern with a wildcard. OpenSSH prior to 6.6 could be
tricked into accepting any enviornment variable that contains the
characters before the wildcard character.

New / changed features:

* ssh(1), sshd(8): this release removes the J-PAKE authentication code.
This code was experimental, never enabled and had been unmaintained
for some time.

* ssh(1): when processing Match blocks, skip 'exec' clauses other clauses
predicates failed to match.

* ssh(1): if hostname canonicalisation is enabled and results in the
destination hostname being changed, then re-parse ssh_config(5) files
using the new destination hostname. This gives 'Host' and 'Match'
directives that use the expanded hostname a chance to be applied.

Bugfixes:

* ssh(1): avoid spurious "getsockname failed: Bad file descriptor" in
ssh -W. bz#2200, debian#738692

* sshd(8): allow the shutdown(2) syscall in seccomp-bpf and systrace
sandbox modes, as it is reachable if the connection is terminated
during the pre-auth phase.

* ssh(1), sshd(8): fix unsigned overflow that in SSH protocol 1 bignum
parsing. Minimum key length checks render this bug unexploitable to
compromise SSH 1 sessions.

* sshd_config(5): clarify behaviour of a keyword that appears in
multiple matching Match blocks. bz#2184

* ssh(1): avoid unnecessary hostname lookups when canonicalisation is
disabled. bz#2205

* sshd(8): avoid sandbox violation crashes in GSSAPI code by caching
the supported list of GSSAPI mechanism OIDs before entering the
sandbox. bz#2107

* ssh(1): fix possible crashes in SOCKS4 parsing caused by assumption
that the SOCKS username is nul-terminated.

* ssh(1): fix regression for UsePrivilegedPort=yes when BindAddress is
not specified.

* ssh(1), sshd(8): fix memory leak in ECDSA signature verification.

* ssh(1): fix matching of 'Host' directives in ssh_config(5) files
to be case-insensitive again (regression in 6.5).

Portable OpenSSH:

* sshd(8): don't fatal if the FreeBSD Capsicum is offered by the
system headers and libc but is not supported by the kernel.
* Fix build using the HP-UX compiler.

下载:ftp://ftp.openbsd.com/pub/OpenBSD/OpenSSH/portable/openssh-6.6p1.tar.gz

来自:oschina开源中国社区
文章评论

共有 0 条评论