OpenBSD CVS

CVS log for www/openssh/security.html


[BACK] Up to [local] / www / openssh

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.75 / (download) / (as text) - annotate - [select for diffs], Sat Apr 20 22:10:39 2024 UTC (5 weeks, 6 days ago) by bentley
Branch: MAIN
CVS Tags: HEAD
Changes since 1.74: +6 -6 lines
Diff to previous 1.74 (unified)

Fix minor syntax errors that crept in.

Revision 1.74 / (download) / (as text) - annotate - [select for diffs], Mon Dec 18 15:07:17 2023 UTC (5 months, 1 week ago) by djm
Branch: MAIN
Changes since 1.73: +30 -0 lines
Diff to previous 1.73 (unified)

openssh-9.6

Revision 1.73 / (download) / (as text) - annotate - [select for diffs], Wed Jul 19 14:32:13 2023 UTC (10 months, 1 week ago) by djm
Branch: MAIN
Changes since 1.72: +0 -1 lines
Diff to previous 1.72 (unified)

less whitespace

Revision 1.72 / (download) / (as text) - annotate - [select for diffs], Wed Jul 19 14:25:55 2023 UTC (10 months, 1 week ago) by djm
Branch: MAIN
Changes since 1.71: +2 -4 lines
Diff to previous 1.71 (unified)

cleaner

Revision 1.71 / (download) / (as text) - annotate - [select for diffs], Wed Jul 19 14:17:44 2023 UTC (10 months, 1 week ago) by djm
Branch: MAIN
Changes since 1.70: +29 -0 lines
Diff to previous 1.70 (unified)

ssh-agent security advisory and OpenSSH 9.3p2 release

Revision 1.70 / (download) / (as text) - annotate - [select for diffs], Tue May 16 08:01:18 2023 UTC (12 months, 2 weeks ago) by dtucker
Branch: MAIN
Changes since 1.69: +2 -2 lines
Diff to previous 1.69 (unified)

The ssh-add smartcard bug is fixed in 9.3 and not 9.2.

Revision 1.69 / (download) / (as text) - annotate - [select for diffs], Thu Mar 16 03:54:48 2023 UTC (14 months, 2 weeks ago) by djm
Branch: MAIN
Changes since 1.68: +1 -1 lines
Diff to previous 1.68 (unified)

typo; spotted by Alexander H

Revision 1.68 / (download) / (as text) - annotate - [select for diffs], Wed Mar 15 22:58:06 2023 UTC (14 months, 2 weeks ago) by djm
Branch: MAIN
Changes since 1.67: +17 -0 lines
Diff to previous 1.67 (unified)

openssh-9.3

Revision 1.67 / (download) / (as text) - annotate - [select for diffs], Thu Feb 2 13:12:49 2023 UTC (15 months, 4 weeks ago) by djm
Branch: MAIN
Changes since 1.66: +50 -0 lines
Diff to previous 1.66 (unified)

security notes for openssh-9.2

Revision 1.66 / (download) / (as text) - annotate - [select for diffs], Sun Sep 26 14:44:16 2021 UTC (2 years, 8 months ago) by djm
Branch: MAIN
Changes since 1.65: +23 -0 lines
Diff to previous 1.65 (unified)

openssh-8.8

Revision 1.65 / (download) / (as text) - annotate - [select for diffs], Wed Mar 3 01:07:17 2021 UTC (3 years, 3 months ago) by djm
Branch: MAIN
Changes since 1.64: +9 -0 lines
Diff to previous 1.64 (unified)

openssh-8.5

Revision 1.64 / (download) / (as text) - annotate - [select for diffs], Sat Apr 25 17:17:28 2020 UTC (4 years, 1 month ago) by schwarze
Branch: MAIN
Changes since 1.63: +9 -0 lines
Diff to previous 1.63 (unified)

In order to properly preserve the historic record, add the missing
list entry for the advisory issued on August 1, 2002.
OK deraadt@

Revision 1.63 / (download) / (as text) - annotate - [select for diffs], Wed Jun 12 07:49:48 2019 UTC (4 years, 11 months ago) by bentley
Branch: MAIN
Changes since 1.62: +52 -92 lines
Diff to previous 1.62 (unified)

Clean up OpenSSH HTML.

Revision 1.62 / (download) / (as text) - annotate - [select for diffs], Sat Jun 1 23:12:53 2019 UTC (5 years ago) by deraadt
Branch: MAIN
Changes since 1.61: +17 -17 lines
Diff to previous 1.61 (unified)

nasty whitespaces

Revision 1.61 / (download) / (as text) - annotate - [select for diffs], Wed May 22 01:42:22 2019 UTC (5 years ago) by tj
Branch: MAIN
Changes since 1.60: +3 -5 lines
Diff to previous 1.60 (unified)

begin replacing many manual <font> and other coloring tags with a much
simpler reference to the css files. this makes the pages smaller and
easier to manage, and will come in handy later on.

ok bentley

Revision 1.60 / (download) / (as text) - annotate - [select for diffs], Wed Oct 4 17:54:26 2017 UTC (6 years, 7 months ago) by djm
Branch: MAIN
Changes since 1.59: +12 -0 lines
Diff to previous 1.59 (unified)

mention sftp-server read-only bug

Revision 1.59 / (download) / (as text) - annotate - [select for diffs], Fri Oct 21 20:02:42 2016 UTC (7 years, 7 months ago) by dtucker
Branch: MAIN
Changes since 1.58: +1 -0 lines
Diff to previous 1.58 (unified)

Add rel=canonical links pointing to https://www.openssh.com.  ok tb@ tj@

Revision 1.58 / (download) / (as text) - annotate - [select for diffs], Sun Oct 16 19:11:30 2016 UTC (7 years, 7 months ago) by tb
Branch: MAIN
Changes since 1.57: +24 -24 lines
Diff to previous 1.57 (unified)

Switch a few links to ftp.openbsd.org, www.libressl.org and www.openssh.org
to https now that the certificates are fully supported. Only fully
qualified links are modified and none that are generated from build/. While
there, fix a few broken links that were found during the conversion.

requested by tj, "yes, but carefully" beck

Revision 1.57 / (download) / (as text) - annotate - [select for diffs], Mon Aug 15 02:22:16 2016 UTC (7 years, 9 months ago) by tb
Branch: MAIN
Changes since 1.56: +5 -5 lines
Diff to previous 1.56 (unified)

tls on openbsd.org is now real:
- link to https://www.openbsd.org from the sub-projects' pages
- make internal links relative
- switch link rel=canonical to https to please some search engines
"go ahead" from beck, "do it!!!!" tj

Revision 1.56 / (download) / (as text) - annotate - [select for diffs], Thu Apr 21 02:46:25 2016 UTC (8 years, 1 month ago) by tj
Branch: MAIN
Changes since 1.55: +15 -5 lines
Diff to previous 1.55 (unified)

move openssh website to css, remove some old files.

Revision 1.55 / (download) / (as text) - annotate - [select for diffs], Mon Mar 14 15:18:24 2016 UTC (8 years, 2 months ago) by deraadt
Branch: MAIN
Changes since 1.54: +17 -0 lines
Diff to previous 1.54 (unified)

mention x11fwd.adv

Revision 1.54 / (download) / (as text) - annotate - [select for diffs], Thu Jan 14 15:07:30 2016 UTC (8 years, 4 months ago) by markus
Branch: MAIN
Changes since 1.53: +6 -6 lines
Diff to previous 1.53 (unified)

fix cve#, date & speling

Revision 1.53 / (download) / (as text) - annotate - [select for diffs], Thu Jan 14 15:00:43 2016 UTC (8 years, 4 months ago) by markus
Branch: MAIN
Changes since 1.52: +16 -0 lines
Diff to previous 1.52 (unified)

update to openssh-7.1p2

Revision 1.52 / (download) / (as text) - annotate - [select for diffs], Fri Dec 18 21:21:05 2015 UTC (8 years, 5 months ago) by deraadt
Branch: MAIN
Changes since 1.51: +2 -3 lines
Diff to previous 1.51 (unified)

some modernization from TJ

Revision 1.51 / (download) / (as text) - annotate - [select for diffs], Fri Aug 21 05:37:18 2015 UTC (8 years, 9 months ago) by djm
Branch: MAIN
Changes since 1.50: +10 -0 lines
Diff to previous 1.50 (unified)

openssh-7.1

Revision 1.50 / (download) / (as text) - annotate - [select for diffs], Tue Aug 11 12:45:33 2015 UTC (8 years, 9 months ago) by djm
Branch: MAIN
Changes since 1.49: +17 -0 lines
Diff to previous 1.49 (unified)

openssh-7.0

Revision 1.49 / (download) / (as text) - annotate - [select for diffs], Sun Jul 12 02:35:52 2015 UTC (8 years, 10 months ago) by deraadt
Branch: MAIN
Changes since 1.48: +83 -27 lines
Diff to previous 1.48 (unified)

Put a date in front of each security hole as they were fixed.  Most were
very very minor, but in case tally is being kept, this shows 1 in 2013,
2 in 2011, 1 in 2009, 3 in 2008, 1 in 2007, 3 in 2006, 2 in 2005, 2 in 2003,
and that's far enough back.
Concern expressed by doug, based on something he saw.

Revision 1.48 / (download) / (as text) - annotate - [select for diffs], Thu Jul 2 05:49:05 2015 UTC (8 years, 11 months ago) by bentley
Branch: MAIN
Changes since 1.47: +0 -3 lines
Diff to previous 1.47 (unified)

Clean up meta tags.

name=distribution, name=keywords, and name=resource-type have no effect
in modern search engines and just clutter up the page source.

From Pavel Plamenov.

Revision 1.47 / (download) / (as text) - annotate - [select for diffs], Fri Jun 26 01:25:10 2015 UTC (8 years, 11 months ago) by bentley
Branch: MAIN
Changes since 1.46: +0 -1 lines
Diff to previous 1.46 (unified)

Remove leftover links to defunct www@.

From Pavel Plamenov on tech@.

Revision 1.46 / (download) / (as text) - annotate - [select for diffs], Sat Feb 7 06:54:38 2015 UTC (9 years, 3 months ago) by bentley
Branch: MAIN
Changes since 1.45: +0 -9 lines
Diff to previous 1.45 (unified)

Remove old footer from OpenSSH pages, as was done to OpenBSD last year.

Revision 1.45 / (download) / (as text) - annotate - [select for diffs], Fri Nov 8 03:10:54 2013 UTC (10 years, 6 months ago) by djm
Branch: MAIN
Changes since 1.44: +8 -1 lines
Diff to previous 1.44 (unified)

openssh-6.4

Revision 1.44 / (download) / (as text) - annotate - [select for diffs], Fri Dec 16 21:35:45 2011 UTC (12 years, 5 months ago) by ajacoutot
Branch: MAIN
Changes since 1.43: +2 -2 lines
Diff to previous 1.43 (unified)

typo: docTYPE -> DOCTYPE

from Steffen Daode Nurpmeso

Revision 1.43 / (download) / (as text) - annotate - [select for diffs], Tue May 3 01:06:46 2011 UTC (13 years, 1 month ago) by djm
Branch: MAIN
Changes since 1.42: +9 -2 lines
Diff to previous 1.42 (unified)

mention 5.8p2 here too

Revision 1.42 / (download) / (as text) - annotate - [select for diffs], Wed Feb 16 22:04:46 2011 UTC (13 years, 3 months ago) by djm
Branch: MAIN
Changes since 1.41: +2 -2 lines
Diff to previous 1.41 (unified)

pasto - link text for recent advisory should read legacy-cert.adv (the
actual link was fine). thanks m.kocielski AT gmail.com

Revision 1.41 / (download) / (as text) - annotate - [select for diffs], Fri Feb 4 01:23:32 2011 UTC (13 years, 3 months ago) by djm
Branch: MAIN
Changes since 1.40: +8 -1 lines
Diff to previous 1.40 (unified)

OpenSSH 5.8

Revision 1.40 / (download) / (as text) - annotate - [select for diffs], Mon Feb 23 02:04:14 2009 UTC (15 years, 3 months ago) by djm
Branch: MAIN
Changes since 1.39: +6 -3 lines
Diff to previous 1.39 (unified)

OpenSSH 5.2

Revision 1.39 / (download) / (as text) - annotate - [select for diffs], Fri Nov 21 10:16:36 2008 UTC (15 years, 6 months ago) by djm
Branch: MAIN
Changes since 1.38: +9 -1 lines
Diff to previous 1.38 (unified)

OpenSSH advisory cbc.adv on CPNI-957037 "Plaintext Recovery
Attack Against SSH"

Revision 1.38 / (download) / (as text) - annotate - [select for diffs], Tue Jul 22 00:09:23 2008 UTC (15 years, 10 months ago) by djm
Branch: MAIN
Changes since 1.37: +5 -1 lines
Diff to previous 1.37 (unified)

openssh-5.1

Revision 1.37 / (download) / (as text) - annotate - [select for diffs], Sat Jul 12 09:50:17 2008 UTC (15 years, 10 months ago) by tobias
Branch: MAIN
Changes since 1.36: +2 -2 lines
Diff to previous 1.36 (unified)

typo

Revision 1.36 / (download) / (as text) - annotate - [select for diffs], Sat Jul 5 04:35:46 2008 UTC (15 years, 11 months ago) by djm
Branch: MAIN
Changes since 1.35: +131 -85 lines
Diff to previous 1.35 (unified)

major whacking: reverse order of entries, so the most revent (& relevant)
are first. Backfill security issues that we neglected to add for recent
version. Add recommended contact address for reporting security
vulnerabilities.

Revision 1.35 / (download) / (as text) - annotate - [select for diffs], Thu Jul 14 04:25:32 2005 UTC (18 years, 10 months ago) by dtucker
Branch: MAIN
Changes since 1.34: +2 -2 lines
Diff to previous 1.34 (unified)

copyright bump for pages updated this year

Revision 1.34 / (download) / (as text) - annotate - [select for diffs], Thu Feb 10 12:04:30 2005 UTC (19 years, 3 months ago) by dtucker
Branch: MAIN
Changes since 1.33: +3 -3 lines
Diff to previous 1.33 (unified)

Correct version number containing fix for the old UseLogin vulnerability.
Pointed out by jo262 ~- at -~ cl.cam.ac.uka.

Revision 1.33 / (download) / (as text) - annotate - [select for diffs], Wed Dec 22 02:06:00 2004 UTC (19 years, 5 months ago) by david
Branch: MAIN
Changes since 1.32: +2 -2 lines
Diff to previous 1.32 (unified)

make small title logo a link back to main page (like all the other web sites)

Revision 1.32 / (download) / (as text) - annotate - [select for diffs], Sun Jan 25 03:14:53 2004 UTC (20 years, 4 months ago) by nick
Branch: MAIN
Changes since 1.31: +2 -2 lines
Diff to previous 1.31 (unified)


Copyright bump.  Most from Saad Kadhi, thanks!

Revision 1.31 / (download) / (as text) - annotate - [select for diffs], Wed Oct 1 08:04:34 2003 UTC (20 years, 8 months ago) by markus
Branch: MAIN
Changes since 1.30: +3 -2 lines
Diff to previous 1.30 (unified)

link CA-2003-24; ok deraadt@

Revision 1.30 / (download) / (as text) - annotate - [select for diffs], Tue Sep 23 14:09:32 2003 UTC (20 years, 8 months ago) by markus
Branch: MAIN
Changes since 1.29: +1 -2 lines
Diff to previous 1.29 (unified)

typo; gwyllion@ace.ulyssis.org

Revision 1.29 / (download) / (as text) - annotate - [select for diffs], Tue Sep 23 12:42:21 2003 UTC (20 years, 8 months ago) by djm
Branch: MAIN
Changes since 1.28: +7 -1 lines
Diff to previous 1.28 (unified)

PAM vulnerabilities in portable OpenSSH

Revision 1.28 / (download) / (as text) - annotate - [select for diffs], Tue Sep 16 22:27:14 2003 UTC (20 years, 8 months ago) by markus
Branch: MAIN
Changes since 1.27: +2 -2 lines
Diff to previous 1.27 (unified)

enter 3.7.1

Revision 1.27 / (download) / (as text) - annotate - [select for diffs], Tue Sep 16 13:09:37 2003 UTC (20 years, 8 months ago) by markus
Branch: MAIN
Changes since 1.26: +6 -1 lines
Diff to previous 1.26 (unified)

buffer.adv

Revision 1.26 / (download) / (as text) - annotate - [select for diffs], Tue Jun 17 17:27:45 2003 UTC (20 years, 11 months ago) by fgsch
Branch: MAIN
Changes since 1.25: +2 -2 lines
Diff to previous 1.25 (unified)

fix html validation; from Xavier Santolaria <xavier at santolaria dot net>.

Revision 1.25 / (download) / (as text) - annotate - [select for diffs], Fri Jun 6 05:35:57 2003 UTC (21 years ago) by fgsch
Branch: MAIN
Changes since 1.24: +2 -2 lines
Diff to previous 1.24 (unified)

fix link to Core SDI's deattack advisory.

Revision 1.24 / (download) / (as text) - annotate - [select for diffs], Thu Jul 18 19:12:28 2002 UTC (21 years, 10 months ago) by provos
Branch: MAIN
Changes since 1.23: +6 -1 lines
Diff to previous 1.23 (unified)

mention june 26th preauth advisory.

Revision 1.23 / (download) / (as text) - annotate - [select for diffs], Sun May 19 12:42:38 2002 UTC (22 years ago) by jufi
Branch: MAIN
Changes since 1.22: +7 -5 lines
Diff to previous 1.22 (unified)


HTML cleanups.

Revision 1.22 / (download) / (as text) - annotate - [select for diffs], Thu Apr 25 14:02:01 2002 UTC (22 years, 1 month ago) by markus
Branch: MAIN
Changes since 1.21: +9 -1 lines
Diff to previous 1.21 (unified)

updated ssh_afstoken advisory

Revision 1.21 / (download) / (as text) - annotate - [select for diffs], Thu Mar 7 14:07:14 2002 UTC (22 years, 3 months ago) by markus
Branch: MAIN
Changes since 1.20: +5 -2 lines
Diff to previous 1.20 (unified)

Off-by-one error in the channel code

Revision 1.20 / (download) / (as text) - annotate - [select for diffs], Sun Jan 20 11:19:06 2002 UTC (22 years, 4 months ago) by jufi
Branch: MAIN
Changes since 1.19: +2 -2 lines
Diff to previous 1.19 (unified)


copyright extended to 2002

Revision 1.19 / (download) / (as text) - annotate - [select for diffs], Fri Dec 7 17:00:15 2001 UTC (22 years, 5 months ago) by markus
Branch: MAIN
Changes since 1.18: +2 -2 lines
Diff to previous 1.18 (unified)

typo

Revision 1.18 / (download) / (as text) - annotate - [select for diffs], Thu Dec 6 17:37:10 2001 UTC (22 years, 6 months ago) by markus
Branch: MAIN
Changes since 1.17: +8 -2 lines
Diff to previous 1.17 (unified)

3.0.2 fixes UseLogin bug.

Revision 1.17 / (download) / (as text) - annotate - [select for diffs], Mon Nov 19 18:46:05 2001 UTC (22 years, 6 months ago) by horacio
Branch: MAIN
Changes since 1.16: +2 -2 lines
Diff to previous 1.16 (unified)

-2001

Revision 1.16 / (download) / (as text) - annotate - [select for diffs], Sun Nov 18 13:02:15 2001 UTC (22 years, 6 months ago) by markus
Branch: MAIN
Changes since 1.15: +17 -1 lines
Diff to previous 1.15 (unified)

add uselogin, x11cookie and malicious servers to access to agent bug.

Revision 1.15 / (download) / (as text) - annotate - [select for diffs], Sun Oct 21 18:20:35 2001 UTC (22 years, 7 months ago) by markus
Branch: MAIN
Changes since 1.14: +6 -1 lines
Diff to previous 1.14 (unified)

add:
"Sep 26, 2001: Weakness in OpenSSH's source IP based access control
for SSH protocol v2 public key authentication."

Revision 1.14 / (download) / (as text) - annotate - [select for diffs], Sat Feb 24 22:23:54 2001 UTC (23 years, 3 months ago) by stevesk
Branch: MAIN
Changes since 1.13: +2 -2 lines
Diff to previous 1.13 (unified)

spelling.

Revision 1.13 / (download) / (as text) - annotate - [select for diffs], Fri Feb 23 00:48:01 2001 UTC (23 years, 3 months ago) by horacio
Branch: MAIN
Changes since 1.12: +11 -11 lines
Diff to previous 1.12 (unified)

remove redundancy + typo

Revision 1.12 / (download) / (as text) - annotate - [select for diffs], Fri Feb 16 13:28:57 2001 UTC (23 years, 3 months ago) by deraadt
Branch: MAIN
Changes since 1.11: +8 -8 lines
Diff to previous 1.11 (unified)

specify when we fixed CORE-20010116

Revision 1.11 / (download) / (as text) - annotate - [select for diffs], Fri Feb 9 04:24:03 2001 UTC (23 years, 3 months ago) by provos
Branch: MAIN
Changes since 1.10: +11 -1 lines
Diff to previous 1.10 (unified)

2.3.1 security note.

Revision 1.10 / (download) / (as text) - annotate - [select for diffs], Thu Feb 8 23:49:04 2001 UTC (23 years, 3 months ago) by provos
Branch: MAIN
Changes since 1.9: +3 -2 lines
Diff to previous 1.9 (unified)

X11 forwarding disabled by default.

Revision 1.9 / (download) / (as text) - annotate - [select for diffs], Thu Feb 8 23:45:41 2001 UTC (23 years, 3 months ago) by provos
Branch: MAIN
Changes since 1.8: +8 -1 lines
Diff to previous 1.8 (unified)

mention SSH-1 Daemon CRC32 Compensation Attack Detector problem.
okay deraadt@

Revision 1.8 / (download) / (as text) - annotate - [select for diffs], Wed Feb 7 22:42:26 2001 UTC (23 years, 3 months ago) by provos
Branch: MAIN
Changes since 1.7: +9 -1 lines
Diff to previous 1.7 (unified)

not vulnerable to bleichenbacher attack from core-sdi advisory,
okay deraadt@

Revision 1.7 / (download) / (as text) - annotate - [select for diffs], Tue Feb 6 22:15:52 2001 UTC (23 years, 3 months ago) by deraadt
Branch: MAIN
Changes since 1.6: +3 -2 lines
Diff to previous 1.6 (unified)

change RC4 description

Revision 1.6 / (download) / (as text) - annotate - [select for diffs], Tue Feb 6 19:31:48 2001 UTC (23 years, 3 months ago) by deraadt
Branch: MAIN
Changes since 1.5: +38 -3 lines
Diff to previous 1.5 (unified)

Xr lots of old security information

Revision 1.5 / (download) / (as text) - annotate - [select for diffs], Thu Nov 23 21:55:28 2000 UTC (23 years, 6 months ago) by jeremy
Branch: MAIN
Changes since 1.4: +2 -2 lines
Diff to previous 1.4 (unified)

November 1999 isn't recent.

Revision 1.4 / (download) / (as text) - annotate - [select for diffs], Wed Nov 17 14:14:15 1999 UTC (24 years, 6 months ago) by provos
Branch: MAIN
Changes since 1.3: +5 -5 lines
Diff to previous 1.3 (unified)

correct title and meta tags

Revision 1.3 / (download) / (as text) - annotate - [select for diffs], Wed Nov 17 05:09:28 1999 UTC (24 years, 6 months ago) by provos
Branch: MAIN
Changes since 1.2: +3 -3 lines
Diff to previous 1.2 (unified)

correct OpenSSH alt tag.

Revision 1.2 / (download) / (as text) - annotate - [select for diffs], Wed Nov 17 00:05:59 1999 UTC (24 years, 6 months ago) by deraadt
Branch: MAIN
Changes since 1.1: +6 -1 lines
Diff to previous 1.1 (unified)

much more meat on the bones

Revision 1.1 / (download) / (as text) - annotate - [select for diffs], Mon Nov 15 11:38:43 1999 UTC (24 years, 6 months ago) by deraadt
Branch: MAIN

so much more

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.