summaryrefslogtreecommitdiff
path: root/CHANGES
diff options
context:
space:
mode:
authorMatt Johnston <matt@ucc.asn.au>2019-03-23 21:46:29 +0800
committerMatt Johnston <matt@ucc.asn.au>2019-03-23 21:46:29 +0800
commit71f818262c995ec7d0fb441a4a908f3866a287a6 (patch)
treef0d219bd7af2dc45b57370d03602c710e7656bc5 /CHANGES
parent07f790db5a9e98ea5d6c4db76416372084af0e96 (diff)
downloaddropbear-71f818262c995ec7d0fb441a4a908f3866a287a6.tar.gz
Diffstat (limited to 'CHANGES')
-rw-r--r--CHANGES40
1 files changed, 40 insertions, 0 deletions
diff --git a/CHANGES b/CHANGES
index 74b843a..cb28fd4 100644
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,43 @@
+2019.77 - 23 March 2019
+
+- Fix server -R option with ECDSA - only advertise one key size which will be accepted.
+ Reported by Peter Krefting, 2018.76 regression.
+
+- Fix server regression in 2018.76 where multiple client -R forwards were all forwarded
+ to the first destination. Reported by Iddo Samet.
+
+- Make failure delay more consistent to avoid revealing valid usernames, set server password
+ limit of 100 characters. Problem reported by usd responsible disclosure team
+
+- Change handling of failed authentication to avoid disclosing valid usernames,
+ CVE-2018-15599.
+
+- Fix dbclient to reliably return the exit code from the remote server.
+ Reported by W. Mike Petullo
+
+- Fix export of 521-bit ECDSA keys, from Christian Hohnstädt
+
+- Add -o Port=xxx option to work with sshfs, from xcko
+
+- Merged fuzzing code, see FUZZER-NOTES.md
+
+- Add a DROPBEAR_SVR_MULTIUSER=0 compile option to run on
+ single-user Linux kernels (CONFIG_MULTIUSER disabled). From Patrick Stewart
+
+- Increase allowed username to 100 characters, reported by W. Mike Petullo
+
+- Update config.sub and config.guess, should now work with RISC-V
+
+- Cygwin compile fix from karel-m
+
+- Don't require GNU sed (accidentally in 2018.76), reported by Samuel Hsu
+
+- Fix for IRIX and writev(), reported by Kazuo Kuroi
+
+- Other fixes and cleanups from François Perrad, Andre McCurdy, Konstantin Demin,
+ Michael Jones, Pawel Rapkiewicz
+
+
2018.76 - 27 February 2018
> > > Configuration/compatibility changes