DockerCLI/vendor/golang.org/x
Sebastiaan van Stijn 1edb10fe30
vendor: bump golang.org/x/crypto bac4c82f6975 (CVE-2020-9283)
full diff: 1d94cc7ab1...bac4c82f69

Version v0.0.0-20200220183623-bac4c82f6975 of golang.org/x/crypto fixes a
vulnerability in the golang.org/x/crypto/ssh package which allowed peers to
cause a panic in SSH servers that accept public keys and in any SSH client.

An attacker can craft an ssh-ed25519 or sk-ssh-ed25519@openssh.com public
key, such that the library will panic when trying to verify a signature
with it. Clients can deliver such a public key and signature to any
golang.org/x/crypto/ssh server with a PublicKeyCallback, and servers can
deliver them to any golang.org/x/crypto/ssh client.

This issue was discovered and reported by Alex Gaynor, Fish in a Barrel,
and is tracked as CVE-2020-9283.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2020-02-20 21:20:47 +01:00
..
crypto vendor: bump golang.org/x/crypto bac4c82f6975 (CVE-2020-9283) 2020-02-20 21:20:47 +01:00
net vendor: update net and sys 2019-06-02 00:39:23 -07:00
oauth2 alias kubernetes api to compose-on-kubernetes implementation 2018-12-28 15:49:17 +01:00
sync bump LK4D4/vndr v0.0.3 and revendor 2019-05-14 16:13:27 -07:00
sys vendor: bump golang.org/x/sys 6d18c012aee9febd81bbf9806760c8c4480e870d 2020-01-07 10:26:26 +01:00
text Bump some dependencies to more recent versions (and tagged if available) 2018-07-25 14:16:41 +02:00
time Bump some dependencies to more recent versions (and tagged if available) 2018-07-25 14:16:41 +02:00