-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Jan 2025 01:35:52 +0100 Source: python-asyncssh Binary: python-asyncssh-doc python3-asyncssh Architecture: all Version: 2.10.1-2+deb12u2 Distribution: bookworm Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Daniel Leidert Description: python-asyncssh-doc - asyncio-based client and server implementation of SSHv2 protocol python3-asyncssh - asyncio-based client and server implementation of SSHv2 protocol Closes: 1055999 1056000 Changes: python-asyncssh (2.10.1-2+deb12u2) bookworm; urgency=medium . * Non-maintainer upload by the Debian LTS team. * debian/patches/CVE-2023-46445-and-CVE-2023-46446.patch: Add patch to fix CVE-2023-46445 and CVE-2023-46446 (Rogue Session Attack, Rogue Extension Negotiation): - Put additional restrictions on when messages are accepted during the SSH handshake to avoid message injection attacks from a rogue client or server (closes: #1055999, #1056000). Checksums-Sha1: a037950723b167eb87d5d8a5dfe329428696749a 416616 python-asyncssh-doc_2.10.1-2+deb12u2_all.deb 4e9e9891a37e5a1be990c8c56d6abc4e3894bfb0 8523 python-asyncssh_2.10.1-2+deb12u2_all-buildd.buildinfo 772ec0dee9fdc3e21741c900410688025d18e163 248076 python3-asyncssh_2.10.1-2+deb12u2_all.deb Checksums-Sha256: eca014689f459dbc963d9fb61f0d0348f75b9765e37767484e6b3edc59863978 416616 python-asyncssh-doc_2.10.1-2+deb12u2_all.deb 8ef2bbc490f7464761766b7a7c1f8243b57abb44e5a894aa8036146687146852 8523 python-asyncssh_2.10.1-2+deb12u2_all-buildd.buildinfo 7a8f059a80856836ff3562e65074be12c87eb008948131650f6c8f39931e2848 248076 python3-asyncssh_2.10.1-2+deb12u2_all.deb Files: 7a9b40357eb9d7de030c9351ba7b6e7b 416616 doc optional python-asyncssh-doc_2.10.1-2+deb12u2_all.deb dcefae243a3844bb2f89a293ea05bf52 8523 python optional python-asyncssh_2.10.1-2+deb12u2_all-buildd.buildinfo 5d7e95dfd487cad0031233951be62c64 248076 python optional python3-asyncssh_2.10.1-2+deb12u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQsM0t1ygJv2xcx3e4cagXJhOTXsFAmd4NKIACgkQ4cagXJhO TXvLHhAArQD2vcMTyY0kbIPtR8Q1wAwkk2VyQ7svC35aGS7OExrUI+5nSMve4O3p BYANeb3ttpNp9+nElpSF71bxBFf/sTw/fHxuta+Il0ImVvOoYn9fPxWaGYbbxSK7 FO16m44tEqCNJpgydc+CIsFn5evij43NVT0aVBch2PPvNChhaqAlj255+FmaYrEr MHuNAbltmNiplVoaBAA7dfof/+g73aZkCbxNf/DUwNs68DCiIgXfybZE2rz7xcOe kSSsv3yaagH7oVgbQuMUc9jZVhLga6X7NxIT4F2Ts9itdR0fLjrZRYXeu3fvey+8 OELwQM2X0Fr8C2SHEzxZwwLzSQ1W/cto09y0Ojz+QVJ84L6AexUkNIKeNYvQUicb jqsA4HsJPmDbo9R6P7UD1gIuQhyqNiwzpw0GD0sGJUZ5CGP/UH8gajhFaVYb+D+F thw59gxcaLegQczFn6HgeYcZtKGIDDGkPMA9lBAq4dhxsuPm3ttCbn6UBMG3DGZc h90rGelSmcYNoxnP+dV7Bbs4mTfwe9A1CJye1Jy/WoAckxVOYR2UjGXKJrWm7Lam UNlzYa96v7UVGBXAy0NVk5dAvvzU1X9LLNB7B5TAahExJ9y73YJAwQ4IYUdshZx6 fujHge3Mc/Ao4ERRG+Yqab3+esywbuJ1JxdyjxA7PtUFUHJT4pc= =l/6+ -----END PGP SIGNATURE-----