1
0
mirror of https://git.yoctoproject.org/poky synced 2026-06-03 13:49:49 +00:00
Files
poky/meta/recipes-connectivity
Ranjitsinh Rathod 3adc98348b openssh: Fix CVE-2023-51385
OS command injection might occur if a user name or host name has shell
metacharacters, and this name is referenced by an expansion token in
certain situations. For example, an untrusted Git repository can have a
submodule with shell metacharacters in a user name or host name.

This patch fixes the above issue

Link: http://archive.ubuntu.com/ubuntu/pool/main/o/openssh/openssh_8.2p1-4ubuntu0.11.debian.tar.xz
Link: https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a

(From OE-Core rev: a0561ca36bd3be8f44d11908caaf8c9ce5f69032)

Signed-off-by: Ranjitsinh Rathod <ranjitsinh.rathod@kpit.com>
Signed-off-by: Ranjitsinh Rathod <ranjitsinhrathod1991@gmail.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2024-01-31 03:51:10 -10:00
..
2023-12-01 04:14:19 -10:00
2023-12-29 05:29:14 -10:00
2020-06-23 11:40:46 +01:00
2022-05-09 11:52:00 +01:00
2019-11-04 13:39:05 +00:00
2024-01-31 03:51:10 -10:00
2023-10-13 05:47:07 -10:00
2023-01-06 17:33:15 +00:00
2023-11-17 06:00:32 -10:00
2020-02-03 13:03:31 +00:00