dropbear is affected by an user enumeration vulnerability similar to the
recent issue in openssh (CVE-2018-15473). Add an upstream patch fixing the
issue.
For more details, see the discussion on the mailing list:
http://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2018q3/002110.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit
|
||
---|---|---|
.. | ||
0001-only-advertise-single-server-ecdsa-key-when-R-is-used.patch | ||
0002-Wait-to-fail-invalid-usernames.patch | ||
Config.in | ||
dropbear.hash | ||
dropbear.mk | ||
dropbear.service | ||
S50dropbear |