Re: CVE-2023-48795: Backporting strict key exchange to older libssh

2024-01-04 Thread Sean Whitton
Hello, On Tue 02 Jan 2024 at 04:32pm +01, Jakub Jelen wrote: > Hi. > Thank you for all the good questions! I will try to reply inline. Many thanks. This will be helpful indeed. -- Sean Whitton signature.asc Description: PGP signature

Re: CVE-2023-48795: Backporting strict key exchange to older libssh

2024-01-02 Thread Jakub Jelen
Hi. Thank you for all the good questions! I will try to reply inline. On Sat, Dec 30, 2023 at 8:41 PM Sean Whitton wrote: > > Hello, > > I am working to backport the fix for CVE-2023-48795 to libssh 0.8.7, > as part of Debian's Long Term Support effort, funded by Freexian SARL. > (I will later

CVE-2023-48795: Backporting strict key exchange to older libssh

2023-12-30 Thread Sean Whitton
Hello, I am working to backport the fix for CVE-2023-48795 to libssh 0.8.7, as part of Debian's Long Term Support effort, funded by Freexian SARL. (I will later be seeking to backport the fix to 0.7.3 and 0.6.3 too, as part of Freexian's Extended Long Term Support effort.) I have two queries