security/dropbear: update to 2020.81

Changelog:
- Fix regression in 2020.79 which prevented connecting with some SSH
  implementations. Increase MAX_PROPOSED_ALGO to 50, and print a log
  message if the limit is hit. This fixes interoperability with sshj
  library (used by PyCharm), and GoAnywhere.
  Reported by Pirmin Walthert and Piotr Jurkiewicz

- Fix building with non-GCC compilers, reported by Kazuo Kuroi

- Fix potential long delay in dbclient, found by OSS Fuzz

- Fix null pointer dereference crash, found by OSS Fuzz

- libtommath now uses the same random source as Dropbear (in 2020.79
  and 2020.80 used getrandom() separately)

- Some fuzzing improvements, start of a dbclient fuzzer
This commit is contained in:
Piotr Kubaj 2020-10-30 11:53:40 +00:00
parent 79daaa5acc
commit 2c29dd15d8
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=553685
2 changed files with 4 additions and 5 deletions

View File

@ -2,8 +2,7 @@
# $FreeBSD$
PORTNAME= dropbear
PORTVERSION= 2020.80
PORTREVISION= 2
PORTVERSION= 2020.81
CATEGORIES= security
MASTER_SITES= https://matt.ucc.asn.au/dropbear/releases/

View File

@ -1,3 +1,3 @@
TIMESTAMP = 1593303429
SHA256 (dropbear-2020.80.tar.bz2) = d927941b91f2da150b2033f1a88b6a47999bf0afb1493a73e9216cffdb5d7949
SIZE (dropbear-2020.80.tar.bz2) = 2287654
TIMESTAMP = 1604058247
SHA256 (dropbear-2020.81.tar.bz2) = 48235d10b37775dbda59341ac0c4b239b82ad6318c31568b985730c788aac53b
SIZE (dropbear-2020.81.tar.bz2) = 2289644