Re: CVE-2023-48795: Backporting strict key exchange to older libssh

2024-01-02 Thread Jakub Jelen
Hi. Thank you for all the good questions! I will try to reply inline. On Sat, Dec 30, 2023 at 8:41 PM Sean Whitton wrote: > > Hello, > > I am working to backport the fix for CVE-2023-48795 to libssh 0.8.7, > as part of Debian's Long Term Support effort, funded by Freexian SARL. > (I will later

Re: CVE-2023-6918: removal of unused evp functions & types

2024-02-26 Thread Jakub Jelen
a look into them, opening a merge request on gitlab would be best. More eyes will see more issues and if there are more people interested in these patches, it might save somebody some more time. We can accept the changes, but we will likely not do release though. Best regards, Jakub Jelen On Sun, Feb