Skip to content

Tags: ClickHouse/libssh

Tags

libssh-0.10.5

Toggle libssh-0.10.5's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.10.5

* Fix CVE-2023-1667: a NULL dereference during rekeying with algorithm
  guessing
* Fix CVE-2023-2283: a possible authorization bypass in
  pki_verify_data_signature under low-memory conditions.
* Fix several memory leaks in GSSAPI handling code
* Escape braces in ProxyCommand created from ProxyJump options for zsh
  compatibility.
* Fix pkg-config path relocation for MinGW
* Improve doxygen documentation
* Fix build with cygwin due to the glob support
* Do not enqueue outgoing packets after sending SSH2_MSG_NEWKEYS
* Add support for SSH_SUPPRESS_DEPRECATED
* Avoid functions declarations without prototype to build with clang 15
* Fix spelling issues
* Avoid expanding KnownHosts, ProxyCommands and IdentityFiles
  repetitively
* Add support sk-* keys through configuration
* Improve checking for Argp library
* Log information about received extensions
* Correctly handle rekey with delayed compression
* Move the EC keys handling to OpenSSL 3.0 API
* Record peer disconnect message
* Avoid deadlock when write buffering occurs and we call poll
  recursively to flush the output buffer
* Disable preauthentication compression by default
* Add CentOS 8 Stream / OpenSSL 1.1.1 to CI
* Add accidentally removed default compile flags
* Solve incorrect parsing of ProxyCommand option

libssh-0.9.7

Toggle libssh-0.9.7's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.9.7

* Fix CVE-2023-1667: a NULL dereference during rekeying with algorithm
  guessing
* Fix CVE-2023-2283: a possible authorization bypass in
  pki_verify_data_signature under low-memory conditions.
* Fix several memory leaks in GSSAPI handling code
* Build and test related backports

libssh-0.10.4

Toggle libssh-0.10.4's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.10.4

* Fixed issues with KDF on big endian

libssh-0.10.3

Toggle libssh-0.10.3's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.10.3

* Fixed possible infinite loop in known hosts checking

libssh-0.10.2

Toggle libssh-0.10.2's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.10.2

* Fixed tilde expansion when handling include directives
* Fixed building the shared torture library
* Made rekey test more robust (fixes running on i586 build systems e.g koji)

libssh-0.10.0

Toggle libssh-0.10.0's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.10.0

* Added support for OpenSSL 3.0
* Added support for mbedTLS 3
* Added support for Smart Cards  (through openssl pkcs11 engine)
* Added support for chacha20-poly1305@openssh.com with libgcrypt
* Added support ed25519 keys in PEM files
* Added support for sk-ecdsa and sk-ed25519 (server side)
* Added support for limiting RSA key sizes and not accepting small one by
  default
* Added support for ssh-agent on Windows
* Added ssh_userauth_publickey_auto_get_current_identity() API
* Added ssh_vlog() API
* Added ssh_send_issue_banner() API
* Added ssh_session_set_disconnect_message() API
* Added new configuration options:
  + IdentityAgent
  + ModuliFile
* Provided X11 client example
* Disabled DSA support at build time by default (will be removed in the next
  release)
* Deprecated the SCP API!
* Deprecated old pubkey, privatekey API
* Avoided some needless large stack buffers to minimize memory footprint
* Removed support for OpenSSL < 1.0.1
* Fixed parsing username@host in login name
* Free global init mutex in the destructor on Windows
* Fixed PEM parsing in mbedtls to support both legacy and new PKCS8 formats

libssh-0.9.6

Toggle libssh-0.9.6's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.9.6

* CVE-2021-3634: Fix possible heap-buffer overflow when rekeying with
  different key exchange mechanism
* Fix several memory leaks on error paths
* Reset pending_call_state on disconnect
* Fix handshake bug with AEAD ciphers and no HMAC overlap
* Use OPENSSL_CRYPTO_LIBRARIES in CMake
* Ignore request success and failure message if they are not expected
* Support more identity files in configuration
* Avoid setting compiler flags directly in CMake
* Support build directories with special characters
* Include stdlib.h to avoid crash in Windows
* Fix sftp_new_channel constructs an invalid object
* Fix Ninja multiple rules error
* Several tests fixes

libssh-0.9.5

Toggle libssh-0.9.5's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.9.5

* CVE-2020-16135: Avoid null pointer dereference in sftpserver (T232)
* Improve handling of library initialization (T222)
* Fix parsing of subsecond times in SFTP (T219)
* Make the documentation reproducible
* Remove deprecated API usage in OpenSSL
* Fix regression of ssh_channel_poll_timeout() returning SSH_AGAIN
* Define version in one place (T226)
* Prevent invalid free when using different C runtimes than OpenSSL (T229)
* Compatibility improvements to testsuite

libssh-0.9.4

Toggle libssh-0.9.4's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.9.4

* Fixed CVE-2020-1730 - Possible DoS in client and server when handling
  AES-CTR keys with OpenSSL
* Added diffie-hellman-group14-sha256
* Fixed serveral possible memory leaks

libssh-0.8.9

Toggle libssh-0.8.9's commit message

Verified

This tag was signed with the committer’s verified signature.
cryptomilk Andreas Schneider
libssh-0.8.9

* Fixed CVE-2020-1730 - Possible DoS in client and server when handling
  AES-CTR keys with OpenSSL