FS#45046 - [openssh] Logjam

Attached to Project: Arch Linux
Opened by Gaelic (gaelic) - Thursday, 21 May 2015, 15:42 GMT
Last edited by Gaetan Bisson (vesath) - Saturday, 04 July 2015, 03:26 GMT
Task Type Bug Report
Category Packages: Core
Status Closed
Assigned To Gaetan Bisson (vesath)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:

Prevent Logjam Intrusion

Additional info:
* package version(s)
all
* config and/or log files etc.
(all?)


Steps to reproduce:

As can be read heere openssh/config should reject every DHgroup smaller 1024Bits https://weakdh.org/

Here's a howto/whattodo:

https://stribika.github.io/2015/01/04/secure-secure-shell.html
This task depends upon

Closed by  Gaetan Bisson (vesath)
Saturday, 04 July 2015, 03:26 GMT
Reason for closing:  Upstream
Additional comments about closing:  openssh-6.9p1-1 in [core]
Comment by Gaetan Bisson (vesath) - Thursday, 21 May 2015, 16:19 GMT
Upstream is aware of this issue and I will update our package as soon as they have decided on a course of action.

Please be more specific regarding what you think should be done with our package, if anything.

Loading...