Files
gitocean/modules
GustedandEarl Warren 3e1b03838e fix: ensure correct ssh public key is used for authentication
- The root cause is described in https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909
- Move to a fork of `github.com/gliderlabs/ssh` that exposes the
permissions that was chosen by `x/crypto/ssh` after succesfully
authenticating, this is the recommended mitigation by the Golang
security team. The fork exposes this, since `gliderlabs/ssh` instead
relies on context values to do so, which is vulnerable to the same
attack, although partially mitigated by the fix in `x/crypto/ssh` it
would not be good practice and defense deep to rely on it.
- Existing tests covers that the functionality is preserved.
- No tests are added to ensure it fixes the described security, the
exploit relies on non-standard SSH behavior it would be too hard to
craft SSH packets to exploit this.
2024-12-12 05:54:07 +01:00
..
2024-11-11 12:44:36 +01:00
2024-11-15 10:59:36 +01:00
2024-08-18 15:19:01 +02:00
2024-08-12 19:11:09 +02:00
2024-11-29 15:42:17 +00:00
2024-08-09 17:44:41 +02:00
2023-02-11 08:39:50 +08:00
2023-12-25 20:13:18 +08:00
2024-09-01 05:42:34 +02:00
2024-07-17 23:07:41 +02:00
2024-11-05 22:47:34 +01:00
2024-08-26 23:43:09 +02:00