diff options
| author | Mark H Weaver <mhw@netris.org> | 2016-08-01 14:02:17 -0400 |
|---|---|---|
| committer | Mark H Weaver <mhw@netris.org> | 2016-08-01 14:27:08 -0400 |
| commit | 742effef5629667b274087adc70b06abab86b252 (patch) | |
| tree | 24c105dc4c0e2b06fdff86295f0edb5af50f8856 /gnu | |
| parent | 660e005c212870e0a791c420824650f39c698b1a (diff) | |
gnu: openssh: Update to 7.3p1.
* gnu/packages/ssh.scm (openssh): Update to 7.3p1.
[source]: Remove patches.
* gnu/packages/patches/openssh-CVE-2015-8325.patch,
gnu/packages/patches/openssh-CVE-2016-6210-1.patch,
gnu/packages/patches/openssh-CVE-2016-6210-2.patch,
gnu/packages/patches/openssh-CVE-2016-6210-3.patch: Delete files.
* gnu/local.mk (dist_patch_DATA): Remove them.
Diffstat (limited to 'gnu')
| -rw-r--r-- | gnu/local.mk | 4 | ||||
| -rw-r--r-- | gnu/packages/patches/openssh-CVE-2015-8325.patch | 31 | ||||
| -rw-r--r-- | gnu/packages/patches/openssh-CVE-2016-6210-1.patch | 114 | ||||
| -rw-r--r-- | gnu/packages/patches/openssh-CVE-2016-6210-2.patch | 111 | ||||
| -rw-r--r-- | gnu/packages/patches/openssh-CVE-2016-6210-3.patch | 60 | ||||
| -rw-r--r-- | gnu/packages/ssh.scm | 8 |
6 files changed, 2 insertions, 326 deletions
diff --git a/gnu/local.mk b/gnu/local.mk index fdc45e10dc7..dcdea86645e 100644 --- a/gnu/local.mk +++ b/gnu/local.mk | |||
| @@ -694,10 +694,6 @@ dist_patch_DATA = \ | |||
| 694 | %D%/packages/patches/openexr-missing-samples.patch \ | 694 | %D%/packages/patches/openexr-missing-samples.patch \ |
| 695 | %D%/packages/patches/openjpeg-CVE-2015-6581.patch \ | 695 | %D%/packages/patches/openjpeg-CVE-2015-6581.patch \ |
| 696 | %D%/packages/patches/openjpeg-use-after-free-fix.patch \ | 696 | %D%/packages/patches/openjpeg-use-after-free-fix.patch \ |
| 697 | %D%/packages/patches/openssh-CVE-2015-8325.patch \ | ||
| 698 | %D%/packages/patches/openssh-CVE-2016-6210-1.patch \ | ||
| 699 | %D%/packages/patches/openssh-CVE-2016-6210-2.patch \ | ||
| 700 | %D%/packages/patches/openssh-CVE-2016-6210-3.patch \ | ||
| 701 | %D%/packages/patches/openssl-runpath.patch \ | 697 | %D%/packages/patches/openssl-runpath.patch \ |
| 702 | %D%/packages/patches/openssl-c-rehash-in.patch \ | 698 | %D%/packages/patches/openssl-c-rehash-in.patch \ |
| 703 | %D%/packages/patches/openssl-CVE-2016-2177.patch \ | 699 | %D%/packages/patches/openssl-CVE-2016-2177.patch \ |
diff --git a/gnu/packages/patches/openssh-CVE-2015-8325.patch b/gnu/packages/patches/openssh-CVE-2015-8325.patch deleted file mode 100644 index 8063e64ea7f..00000000000 --- a/gnu/packages/patches/openssh-CVE-2015-8325.patch +++ /dev/null | |||
| @@ -1,31 +0,0 @@ | |||
| 1 | From 85bdcd7c92fe7ff133bbc4e10a65c91810f88755 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Damien Miller <djm@mindrot.org> | ||
| 3 | Date: Wed, 13 Apr 2016 10:39:57 +1000 | ||
| 4 | Subject: ignore PAM environment vars when UseLogin=yes | ||
| 5 | |||
| 6 | If PAM is configured to read user-specified environment variables | ||
| 7 | and UseLogin=yes in sshd_config, then a hostile local user may | ||
| 8 | attack /bin/login via LD_PRELOAD or similar environment variables | ||
| 9 | set via PAM. | ||
| 10 | |||
| 11 | CVE-2015-8325, found by Shayan Sadigh, via Colin Watson | ||
| 12 | --- | ||
| 13 | session.c | 2 +- | ||
| 14 | 1 file changed, 1 insertion(+), 1 deletion(-) | ||
| 15 | |||
| 16 | diff --git a/session.c b/session.c | ||
| 17 | index 4859245..4653b09 100644 | ||
| 18 | --- a/session.c | ||
| 19 | +++ b/session.c | ||
| 20 | @@ -1322,7 +1322,7 @@ do_setup_env(Session *s, const char *shell) | ||
| 21 | * Pull in any environment variables that may have | ||
| 22 | * been set by PAM. | ||
| 23 | */ | ||
| 24 | - if (options.use_pam) { | ||
| 25 | + if (options.use_pam && !options.use_login) { | ||
| 26 | char **p; | ||
| 27 | |||
| 28 | p = fetch_pam_child_environment(); | ||
| 29 | -- | ||
| 30 | cgit v0.11.2 | ||
| 31 | |||
diff --git a/gnu/packages/patches/openssh-CVE-2016-6210-1.patch b/gnu/packages/patches/openssh-CVE-2016-6210-1.patch deleted file mode 100644 index 9b46ec12a91..00000000000 --- a/gnu/packages/patches/openssh-CVE-2016-6210-1.patch +++ /dev/null | |||
| @@ -1,114 +0,0 @@ | |||
| 1 | From e5ef9d3942cebda819a6fd81647b51c8d87d23df Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Darren Tucker <dtucker@zip.com.au> | ||
| 3 | Date: Fri, 15 Jul 2016 13:32:45 +1000 | ||
| 4 | Subject: Determine appropriate salt for invalid users. | ||
| 5 | |||
| 6 | When sshd is processing a non-PAM login for a non-existent user it uses | ||
| 7 | the string from the fakepw structure as the salt for crypt(3)ing the | ||
| 8 | password supplied by the client. That string has a Blowfish prefix, so on | ||
| 9 | systems that don't understand that crypt will fail fast due to an invalid | ||
| 10 | salt, and even on those that do it may have significantly different timing | ||
| 11 | from the hash methods used for real accounts (eg sha512). This allows | ||
| 12 | user enumeration by, eg, sending large password strings. This was noted | ||
| 13 | by EddieEzra.Harari at verint.com (CVE-2016-6210). | ||
| 14 | |||
| 15 | To mitigate, use the same hash algorithm that root uses for hashing | ||
| 16 | passwords for users that do not exist on the system. ok djm@ | ||
| 17 | |||
| 18 | Origin: upstream, https://anongit.mindrot.org/openssh.git/commit/?id=9286875a73b2de7736b5e50692739d314cd8d9dc | ||
| 19 | Bug-Debian: https://bugs.debian.org/831902 | ||
| 20 | Last-Update: 2016-07-22 | ||
| 21 | |||
| 22 | Patch-Name: CVE-2016-6210-1.patch | ||
| 23 | --- | ||
| 24 | auth-passwd.c | 12 ++++++++---- | ||
| 25 | openbsd-compat/xcrypt.c | 34 ++++++++++++++++++++++++++++++++++ | ||
| 26 | 2 files changed, 42 insertions(+), 4 deletions(-) | ||
| 27 | |||
| 28 | diff --git a/auth-passwd.c b/auth-passwd.c | ||
| 29 | index 63ccf3c..530b5d4 100644 | ||
| 30 | --- a/auth-passwd.c | ||
| 31 | +++ b/auth-passwd.c | ||
| 32 | @@ -193,7 +193,7 @@ int | ||
| 33 | sys_auth_passwd(Authctxt *authctxt, const char *password) | ||
| 34 | { | ||
| 35 | struct passwd *pw = authctxt->pw; | ||
| 36 | - char *encrypted_password; | ||
| 37 | + char *encrypted_password, *salt = NULL; | ||
| 38 | |||
| 39 | /* Just use the supplied fake password if authctxt is invalid */ | ||
| 40 | char *pw_password = authctxt->valid ? shadow_pw(pw) : pw->pw_passwd; | ||
| 41 | @@ -202,9 +202,13 @@ sys_auth_passwd(Authctxt *authctxt, const char *password) | ||
| 42 | if (strcmp(pw_password, "") == 0 && strcmp(password, "") == 0) | ||
| 43 | return (1); | ||
| 44 | |||
| 45 | - /* Encrypt the candidate password using the proper salt. */ | ||
| 46 | - encrypted_password = xcrypt(password, | ||
| 47 | - (pw_password[0] && pw_password[1]) ? pw_password : "xx"); | ||
| 48 | + /* | ||
| 49 | + * Encrypt the candidate password using the proper salt, or pass a | ||
| 50 | + * NULL and let xcrypt pick one. | ||
| 51 | + */ | ||
| 52 | + if (authctxt->valid && pw_password[0] && pw_password[1]) | ||
| 53 | + salt = pw_password; | ||
| 54 | + encrypted_password = xcrypt(password, salt); | ||
| 55 | |||
| 56 | /* | ||
| 57 | * Authentication is accepted if the encrypted passwords | ||
| 58 | diff --git a/openbsd-compat/xcrypt.c b/openbsd-compat/xcrypt.c | ||
| 59 | index 8577cbd..8913bb8 100644 | ||
| 60 | --- a/openbsd-compat/xcrypt.c | ||
| 61 | +++ b/openbsd-compat/xcrypt.c | ||
| 62 | @@ -25,6 +25,7 @@ | ||
| 63 | #include "includes.h" | ||
| 64 | |||
| 65 | #include <sys/types.h> | ||
| 66 | +#include <string.h> | ||
| 67 | #include <unistd.h> | ||
| 68 | #include <pwd.h> | ||
| 69 | |||
| 70 | @@ -62,11 +63,44 @@ | ||
| 71 | # define crypt DES_crypt | ||
| 72 | # endif | ||
| 73 | |||
| 74 | +/* | ||
| 75 | + * Pick an appropriate password encryption type and salt for the running | ||
| 76 | + * system. | ||
| 77 | + */ | ||
| 78 | +static const char * | ||
| 79 | +pick_salt(void) | ||
| 80 | +{ | ||
| 81 | + struct passwd *pw; | ||
| 82 | + char *passwd, *p; | ||
| 83 | + size_t typelen; | ||
| 84 | + static char salt[32]; | ||
| 85 | + | ||
| 86 | + if (salt[0] != '\0') | ||
| 87 | + return salt; | ||
| 88 | + strlcpy(salt, "xx", sizeof(salt)); | ||
| 89 | + if ((pw = getpwuid(0)) == NULL) | ||
| 90 | + return salt; | ||
| 91 | + passwd = shadow_pw(pw); | ||
| 92 | + if (passwd[0] != '$' || (p = strrchr(passwd + 1, '$')) == NULL) | ||
| 93 | + return salt; /* no $, DES */ | ||
| 94 | + typelen = p - passwd + 1; | ||
| 95 | + strlcpy(salt, passwd, MIN(typelen, sizeof(salt))); | ||
| 96 | + explicit_bzero(passwd, strlen(passwd)); | ||
| 97 | + return salt; | ||
| 98 | +} | ||
| 99 | + | ||
| 100 | char * | ||
| 101 | xcrypt(const char *password, const char *salt) | ||
| 102 | { | ||
| 103 | char *crypted; | ||
| 104 | |||
| 105 | + /* | ||
| 106 | + * If we don't have a salt we are encrypting a fake password for | ||
| 107 | + * for timing purposes. Pick an appropriate salt. | ||
| 108 | + */ | ||
| 109 | + if (salt == NULL) | ||
| 110 | + salt = pick_salt(); | ||
| 111 | + | ||
| 112 | # ifdef HAVE_MD5_PASSWORDS | ||
| 113 | if (is_md5_salt(salt)) | ||
| 114 | crypted = md5_crypt(password, salt); | ||
diff --git a/gnu/packages/patches/openssh-CVE-2016-6210-2.patch b/gnu/packages/patches/openssh-CVE-2016-6210-2.patch deleted file mode 100644 index 1c580f90b95..00000000000 --- a/gnu/packages/patches/openssh-CVE-2016-6210-2.patch +++ /dev/null | |||
| @@ -1,111 +0,0 @@ | |||
| 1 | From dde63f7f998ac3812a26bbb2c1b2947f24fcd060 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Darren Tucker <dtucker@zip.com.au> | ||
| 3 | Date: Fri, 15 Jul 2016 13:49:44 +1000 | ||
| 4 | Subject: Mitigate timing of disallowed users PAM logins. | ||
| 5 | |||
| 6 | When sshd decides to not allow a login (eg PermitRootLogin=no) and | ||
| 7 | it's using PAM, it sends a fake password to PAM so that the timing for | ||
| 8 | the failure is not noticeably different whether or not the password | ||
| 9 | is correct. This behaviour can be detected by sending a very long | ||
| 10 | password string which is slower to hash than the fake password. | ||
| 11 | |||
| 12 | Mitigate by constructing an invalid password that is the same length | ||
| 13 | as the one from the client and thus takes the same time to hash. | ||
| 14 | Diff from djm@ | ||
| 15 | |||
| 16 | Origin: upstream, https://anongit.mindrot.org/openssh.git/commit/?id=283b97ff33ea2c641161950849931bd578de6946 | ||
| 17 | Bug-Debian: https://bugs.debian.org/831902 | ||
| 18 | Last-Update: 2016-07-22 | ||
| 19 | |||
| 20 | Patch-Name: CVE-2016-6210-2.patch | ||
| 21 | --- | ||
| 22 | auth-pam.c | 35 +++++++++++++++++++++++++++++++---- | ||
| 23 | 1 file changed, 31 insertions(+), 4 deletions(-) | ||
| 24 | |||
| 25 | diff --git a/auth-pam.c b/auth-pam.c | ||
| 26 | index 8425af1..abd6a5e 100644 | ||
| 27 | --- a/auth-pam.c | ||
| 28 | +++ b/auth-pam.c | ||
| 29 | @@ -232,7 +232,6 @@ static int sshpam_account_status = -1; | ||
| 30 | static char **sshpam_env = NULL; | ||
| 31 | static Authctxt *sshpam_authctxt = NULL; | ||
| 32 | static const char *sshpam_password = NULL; | ||
| 33 | -static char badpw[] = "\b\n\r\177INCORRECT"; | ||
| 34 | |||
| 35 | /* Some PAM implementations don't implement this */ | ||
| 36 | #ifndef HAVE_PAM_GETENVLIST | ||
| 37 | @@ -810,12 +809,35 @@ sshpam_query(void *ctx, char **name, char **info, | ||
| 38 | return (-1); | ||
| 39 | } | ||
| 40 | |||
| 41 | +/* | ||
| 42 | + * Returns a junk password of identical length to that the user supplied. | ||
| 43 | + * Used to mitigate timing attacks against crypt(3)/PAM stacks that | ||
| 44 | + * vary processing time in proportion to password length. | ||
| 45 | + */ | ||
| 46 | +static char * | ||
| 47 | +fake_password(const char *wire_password) | ||
| 48 | +{ | ||
| 49 | + const char junk[] = "\b\n\r\177INCORRECT"; | ||
| 50 | + char *ret = NULL; | ||
| 51 | + size_t i, l = wire_password != NULL ? strlen(wire_password) : 0; | ||
| 52 | + | ||
| 53 | + if (l >= INT_MAX) | ||
| 54 | + fatal("%s: password length too long: %zu", __func__, l); | ||
| 55 | + | ||
| 56 | + ret = malloc(l + 1); | ||
| 57 | + for (i = 0; i < l; i++) | ||
| 58 | + ret[i] = junk[i % (sizeof(junk) - 1)]; | ||
| 59 | + ret[i] = '\0'; | ||
| 60 | + return ret; | ||
| 61 | +} | ||
| 62 | + | ||
| 63 | /* XXX - see also comment in auth-chall.c:verify_response */ | ||
| 64 | static int | ||
| 65 | sshpam_respond(void *ctx, u_int num, char **resp) | ||
| 66 | { | ||
| 67 | Buffer buffer; | ||
| 68 | struct pam_ctxt *ctxt = ctx; | ||
| 69 | + char *fake; | ||
| 70 | |||
| 71 | debug2("PAM: %s entering, %u responses", __func__, num); | ||
| 72 | switch (ctxt->pam_done) { | ||
| 73 | @@ -836,8 +858,11 @@ sshpam_respond(void *ctx, u_int num, char **resp) | ||
| 74 | (sshpam_authctxt->pw->pw_uid != 0 || | ||
| 75 | options.permit_root_login == PERMIT_YES)) | ||
| 76 | buffer_put_cstring(&buffer, *resp); | ||
| 77 | - else | ||
| 78 | - buffer_put_cstring(&buffer, badpw); | ||
| 79 | + else { | ||
| 80 | + fake = fake_password(*resp); | ||
| 81 | + buffer_put_cstring(&buffer, fake); | ||
| 82 | + free(fake); | ||
| 83 | + } | ||
| 84 | if (ssh_msg_send(ctxt->pam_psock, PAM_AUTHTOK, &buffer) == -1) { | ||
| 85 | buffer_free(&buffer); | ||
| 86 | return (-1); | ||
| 87 | @@ -1181,6 +1206,7 @@ sshpam_auth_passwd(Authctxt *authctxt, const char *password) | ||
| 88 | { | ||
| 89 | int flags = (options.permit_empty_passwd == 0 ? | ||
| 90 | PAM_DISALLOW_NULL_AUTHTOK : 0); | ||
| 91 | + char *fake = NULL; | ||
| 92 | |||
| 93 | if (!options.use_pam || sshpam_handle == NULL) | ||
| 94 | fatal("PAM: %s called when PAM disabled or failed to " | ||
| 95 | @@ -1196,7 +1222,7 @@ sshpam_auth_passwd(Authctxt *authctxt, const char *password) | ||
| 96 | */ | ||
| 97 | if (!authctxt->valid || (authctxt->pw->pw_uid == 0 && | ||
| 98 | options.permit_root_login != PERMIT_YES)) | ||
| 99 | - sshpam_password = badpw; | ||
| 100 | + sshpam_password = fake = fake_password(password); | ||
| 101 | |||
| 102 | sshpam_err = pam_set_item(sshpam_handle, PAM_CONV, | ||
| 103 | (const void *)&passwd_conv); | ||
| 104 | @@ -1206,6 +1232,7 @@ sshpam_auth_passwd(Authctxt *authctxt, const char *password) | ||
| 105 | |||
| 106 | sshpam_err = pam_authenticate(sshpam_handle, flags); | ||
| 107 | sshpam_password = NULL; | ||
| 108 | + free(fake); | ||
| 109 | if (sshpam_err == PAM_SUCCESS && authctxt->valid) { | ||
| 110 | debug("PAM: password authentication accepted for %.100s", | ||
| 111 | authctxt->user); | ||
diff --git a/gnu/packages/patches/openssh-CVE-2016-6210-3.patch b/gnu/packages/patches/openssh-CVE-2016-6210-3.patch deleted file mode 100644 index 303c34ee1b2..00000000000 --- a/gnu/packages/patches/openssh-CVE-2016-6210-3.patch +++ /dev/null | |||
| @@ -1,60 +0,0 @@ | |||
| 1 | From abde8dda29c2db2405d6fbca2fe022430e2c1177 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Darren Tucker <dtucker@zip.com.au> | ||
| 3 | Date: Thu, 21 Jul 2016 14:17:31 +1000 | ||
| 4 | Subject: Search users for one with a valid salt. | ||
| 5 | |||
| 6 | If the root account is locked (eg password "!!" or "*LK*") keep looking | ||
| 7 | until we find a user with a valid salt to use for crypting passwords of | ||
| 8 | invalid users. ok djm@ | ||
| 9 | |||
| 10 | Origin: upstream, https://anongit.mindrot.org/openssh.git/commit/?id=dbf788b4d9d9490a5fff08a7b09888272bb10fcc | ||
| 11 | Bug-Debian: https://bugs.debian.org/831902 | ||
| 12 | Last-Update: 2016-07-22 | ||
| 13 | |||
| 14 | Patch-Name: CVE-2016-6210-3.patch | ||
| 15 | --- | ||
| 16 | openbsd-compat/xcrypt.c | 24 +++++++++++++++--------- | ||
| 17 | 1 file changed, 15 insertions(+), 9 deletions(-) | ||
| 18 | |||
| 19 | diff --git a/openbsd-compat/xcrypt.c b/openbsd-compat/xcrypt.c | ||
| 20 | index 8913bb8..cf6a9b9 100644 | ||
| 21 | --- a/openbsd-compat/xcrypt.c | ||
| 22 | +++ b/openbsd-compat/xcrypt.c | ||
| 23 | @@ -65,7 +65,9 @@ | ||
| 24 | |||
| 25 | /* | ||
| 26 | * Pick an appropriate password encryption type and salt for the running | ||
| 27 | - * system. | ||
| 28 | + * system by searching through accounts until we find one that has a valid | ||
| 29 | + * salt. Usually this will be root unless the root account is locked out. | ||
| 30 | + * If we don't find one we return a traditional DES-based salt. | ||
| 31 | */ | ||
| 32 | static const char * | ||
| 33 | pick_salt(void) | ||
| 34 | @@ -78,14 +80,18 @@ pick_salt(void) | ||
| 35 | if (salt[0] != '\0') | ||
| 36 | return salt; | ||
| 37 | strlcpy(salt, "xx", sizeof(salt)); | ||
| 38 | - if ((pw = getpwuid(0)) == NULL) | ||
| 39 | - return salt; | ||
| 40 | - passwd = shadow_pw(pw); | ||
| 41 | - if (passwd[0] != '$' || (p = strrchr(passwd + 1, '$')) == NULL) | ||
| 42 | - return salt; /* no $, DES */ | ||
| 43 | - typelen = p - passwd + 1; | ||
| 44 | - strlcpy(salt, passwd, MIN(typelen, sizeof(salt))); | ||
| 45 | - explicit_bzero(passwd, strlen(passwd)); | ||
| 46 | + setpwent(); | ||
| 47 | + while ((pw = getpwent()) != NULL) { | ||
| 48 | + passwd = shadow_pw(pw); | ||
| 49 | + if (passwd[0] == '$' && (p = strrchr(passwd+1, '$')) != NULL) { | ||
| 50 | + typelen = p - passwd + 1; | ||
| 51 | + strlcpy(salt, passwd, MIN(typelen, sizeof(salt))); | ||
| 52 | + explicit_bzero(passwd, strlen(passwd)); | ||
| 53 | + goto out; | ||
| 54 | + } | ||
| 55 | + } | ||
| 56 | + out: | ||
| 57 | + endpwent(); | ||
| 58 | return salt; | ||
| 59 | } | ||
| 60 | |||
diff --git a/gnu/packages/ssh.scm b/gnu/packages/ssh.scm index 6953bad58a6..bca443390db 100644 --- a/gnu/packages/ssh.scm +++ b/gnu/packages/ssh.scm | |||
| @@ -124,7 +124,7 @@ a server that supports the SSH-2 protocol.") | |||
| 124 | (define-public openssh | 124 | (define-public openssh |
| 125 | (package | 125 | (package |
| 126 | (name "openssh") | 126 | (name "openssh") |
| 127 | (version "7.2p2") | 127 | (version "7.3p1") |
| 128 | (source (origin | 128 | (source (origin |
| 129 | (method url-fetch) | 129 | (method url-fetch) |
| 130 | (uri (let ((tail (string-append name "-" version ".tar.gz"))) | 130 | (uri (let ((tail (string-append name "-" version ".tar.gz"))) |
| @@ -135,11 +135,7 @@ a server that supports the SSH-2 protocol.") | |||
| 135 | (string-append "http://ftp2.fr.openbsd.org/pub/OpenBSD/OpenSSH/portable/" | 135 | (string-append "http://ftp2.fr.openbsd.org/pub/OpenBSD/OpenSSH/portable/" |
| 136 | tail)))) | 136 | tail)))) |
| 137 | (sha256 (base32 | 137 | (sha256 (base32 |
| 138 | "132lh9aanb0wkisji1d6cmsxi520m8nh7c7i9wi6m1s3l38q29x7")) | 138 | "1k5y1wi29d47cgizbryxrhc1fbjsba2x8l5mqfa9b9nadnd9iyrz")))) |
| 139 | (patches (search-patches "openssh-CVE-2015-8325.patch" | ||
| 140 | "openssh-CVE-2016-6210-1.patch" | ||
| 141 | "openssh-CVE-2016-6210-2.patch" | ||
| 142 | "openssh-CVE-2016-6210-3.patch")))) | ||
| 143 | (build-system gnu-build-system) | 139 | (build-system gnu-build-system) |
| 144 | (inputs `(("groff" ,groff) | 140 | (inputs `(("groff" ,groff) |
| 145 | ("openssl" ,openssl) | 141 | ("openssl" ,openssl) |
