Rilascio di OpenSSH 10.1

È stato rilasciato OpenSSH 10.1, un'implementazione open source di client e server per operare con i protocolli SSH 2.0 e SFTP.

Principali modifiche:

  • È stato risolto un problema di sicurezza che consentiva a un attaccante di iniettare comandi shell tramite manipolazioni di caratteri speciali nel nome utente o nell'URI, che potevano essere eseguiti all'avvio di un comando specificato tramite l'impostazione «ProxyCommand» e contenente il segnaposto «%u». Il problema colpisce solo i sistemi che consentono l'uso di nomi utente o URI derivati da fonti non attendibili durante l'esecuzione di ssh.

    Per bloccare attacchi simili, l'uso di caratteri di controllo nei nomi utente specificati al lancio dalla riga di comando o iniettati nelle impostazioni tramite sequenze %- è stato vietato. È anche vietato l'uso del carattere nullo («\0») negli URI ssh://. Fanno eccezione solo i nomi specificati nel file di configurazione (si presume che i dati in questo file di configurazione siano di fiducia).

  • Gli strumenti ssh e ssh-agent hanno aggiunto il supporto per le chiavi ed25519, memorizzate nei token PKCS#11.
  • Nel file di configurazione ssh_config è stata aggiunta l'impostazione RefuseConnection, che durante l'elaborazione nella sezione attiva termina il processo con un messaggio di errore senza tentare di stabilire la connessione. Match host foo RefuseConnection «host foo non è più in uso, collegati all'host bar»
  • In ssh e sshd sono stati aggiunti gestori del segnale SIGINFO per registrare nel log informazioni sulla sessione e sul canale attivo.
  • In sshd, in caso di rifiuto dell'autenticazione dell'utente tramite certificato, viene registrata nel log non solo la causa del blocco dell'accesso, ma anche informazioni dettagliate per identificare il certificato problematico.
  • In sshd è stata aggiunta una verifica del numero di display X11 rispetto all'offset specificato nella direttiva X11DisplayOffset.
  • Nel set di unit-test sono state aggiunte funzionalità per la misurazione delle prestazioni, attivabili durante l'esecuzione di «make UNITTEST_BENCHMARK=yes» in OpenBSD o «make unit-bench» negli altri sistemi.

Modifiche che potrebbero compromettere la compatibilità inversa:

  • In ssh, a warning has been added when using a key exchange algorithm that is not resistant to brute-force attacks by quantum computers. The warning has been introduced due to the risk of future attacks utilizing previously captured traffic dumps. To disable the warning, the WarnWeakCrypto option has been added to ssh_config.
    Match host unsafe.example.com
    WarnWeakCrypto no
  • In ssh and sshd, the handling of DSCP (IPQoS) quality of service parameters has been significantly changed. For interactive traffic, the EF (Expedited Forwarding) class is now set by default for higher priority handling in wireless networks. For non-interactive traffic, the class is set to the default used by the operating system. The traffic class can be changed using the IPQoS setting in ssh_config and sshd_config. ToS (type-of-service) parameters for IPv4 in the IPQoS directive have been deprecated (DSCP has replaced ToS).
  • In ssh-add, when adding a certificate to the ssh-agent, the certificate's lifetime is set to a value that is 5 minutes longer than its expiration date (to allow for the automatic removal of expired certificates). To disable this behavior, the option "-N" has been added to ssh-add.
  • Support for XMSS keys has been removed, which was marked as experimental and never enabled by default.
  • Unix sockets created by the ssh-agent and sshd processes have been moved from the /tmp directory to ~/.ssh/agent, ensuring that access to these sockets from isolated processes with restricted filesystem access is impossible, while access to /tmp remains open.

In future releases, SHA1 DNS SSHFP records will be deprecated due to reliability issues with the SHA1 hash function. These records will be ignored, and the command "ssh-keygen -r" will only generate SHA256 SSHFP records.

Fonte: opennet.ru

Acquista hosting affidabile per siti web con protezione DDoS, VPS VDS server 🔥 Acquista hosting affidabile per siti web con protezione DDoS, VPS VDS server | ProHoster