ºìÁªLinuxÃÅ»§
Linux°ïÖú

OpenSSH 7.1·¢²¼£¬bugÐÞ¸´°æ±¾

·¢²¼Ê±¼ä:2015-08-22 09:32:25À´Ô´:ºìÁª×÷Õß:empast
OpenSSH 7.1 ·¢²¼£¬OpenSSH£¨Open Secure Shell£©ÊÇʹÓÃSSH͸¹ý¼ÆËã»úÍøÂç¼ÓÃÜͨѶµÄʵÏÖ¡£ËüÊÇÈ¡´úÓÉSSH Communications SecurityËùÌṩµÄÉÌÓð汾µÄ¿ª·ÅÔ´´úÂë·½°¸¡£Ä¿Ç°OpenSSHÊÇOpenBSDµÄ×Ӽƻ®¡£

OpenSSH³£³£±»ÎóÈÏÒÔΪÓëOpenSSLÓйØÁª£¬µ«Êµ¼ÊÉÏÕâÁ½¸ö¼Æ»®µÄÓв»Í¬µÄÄ¿µÄ£¬²»Í¬µÄ·¢Õ¹ÍŶӣ¬Ãû³ÆÏà½üÖ»ÊÇÒòΪÁ½ÕßÓÐͬÑùµÄÈí¼þ·¢Õ¹Ä¿±ê©¤©¤Ìṩ¿ª·ÅÔ´´úÂëµÄ¼ÓÃÜͨѶÈí¼þ¡£

δÀ´ÆúÓÃ֪ͨ
=========================
ϸö°æ±¾»áÆúÓÃһЩ´«Í³ÃÜÂëѧ£º

* Refusing all RSA keys smaller than 1024 bits (the current minimum
is 768 bits)

* Several ciphers will be disabled by default: blowfish-cbc,
cast128-cbc, all arcfour variants and the rijndael-cbc aliases
for AES.

* MD5-based HMAC algorithms will be disabled by default.

OpenSSh 7.1 Ïà±È OpenSSH 7.0 µÄ¸Ä½ø
=========================

´Ë°æ±¾ÊǸö bug ÐÞ¸´°æ±¾

°²È«¸üÐÂ
--------

* sshd(8): OpenSSH 7.0 contained a logic error in PermitRootLogin=
prohibit-password/without-password that could, depending on
compile-time configuration, permit password authentication to
root while preventing other forms of authentication. This problem
was reported by Mantas Mikulenas.

Bug ÐÞ¸´
--------

* ssh(1), sshd(8): add compatability workarounds for FuTTY

* ssh(1), sshd(8): refine compatability workarounds for WinSCP

* Fix a number of memory faults (double-free, free of uninitialised
memory, etc) in ssh(1) and ssh-keygen(1). Reported by Mateusz
Kocielski.

Checksums:
==========

- SHA1 (openssh-7.1.tar.gz) = 06c1db39f33831fe004726e013b2cf84f1889042
- SHA256 (openssh-7.1.tar.gz) = H7U1se9EoBmhkKi2i7lqpMX9QHdDTsgpu7kd5VZUGSY=

- SHA1 (openssh-7.1p1.tar.gz) = ed22af19f962262c493fcc6ed8c8826b2761d9b6
- SHA256 (openssh-7.1p1.tar.gz) = /AptLR0GPVxm3/2VJJPQzaJWytIE9oHeD4TvhbKthCg=

Èí¼þÏêÇ飺http://www.openssh.com/txt/release-7.1

ÏÂÔØµØÖ·£ºhttp://www.openssh.com/portable.html

À´×Ô:¿ªÔ´ÖйúÉçÇø
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ