moby--moby/vendor
Sebastiaan van Stijn 917b44799d
vendor: golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd
full diff: 5770296d90...3147a52a75

This version contains a fix for CVE-2022-27191 (not sure if it affects us).

From the golang mailing list:

    Hello gophers,

    Version v0.0.0-20220315160706-3147a52a75dd of golang.org/x/crypto/ssh implements
    client authentication support for signature algorithms based on SHA-2 for use with
    existing RSA keys.

    Previously, a client would fail to authenticate with RSA keys to servers that
    reject signature algorithms based on SHA-1. This includes OpenSSH 8.8 by default
    and—starting today March 15, 2022 for recently uploaded keys.

    We are providing this announcement as the error (“ssh: unable to authenticate”)
    might otherwise be difficult to troubleshoot.

    Version v0.0.0-20220314234659-1baeb1ce4c0b (included in the version above) also
    fixes a potential security issue where an attacker could cause a crash in a
    golang.org/x/crypto/ssh server under these conditions:

    - The server has been configured by passing a Signer to ServerConfig.AddHostKey.
    - The Signer passed to AddHostKey does not also implement AlgorithmSigner.
    - The Signer passed to AddHostKey does return a key of type “ssh-rsa” from its PublicKey method.

    Servers that only use Signer implementations provided by the ssh package are
    unaffected. This is CVE-2022-27191.

    Alla prossima,

    Filippo for the Go Security team

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2022-03-17 13:59:03 +01:00
..
cloud.google.com/go vendor: cloud.google.com/go v0.92.0, google.golang.org/api v0.54.0 2022-03-11 20:01:57 +01:00
code.cloudfoundry.org/clock bump docker/swarmkit 59163bf75df38489d4a10392265d27156dc473c5 2019-04-15 18:04:36 +02:00
github.com vendor: cloud.google.com/go v0.92.0, google.golang.org/api v0.54.0 2022-03-11 20:01:57 +01:00
go.etcd.io vendor: github.com/docker/swarmkit 616e8db4c3b0 2022-03-10 17:48:09 -05:00
go.opencensus.io Unpin grpc, protobuf dependencies 2022-03-10 17:48:10 -05:00
go.uber.org vendor: github.com/docker/swarmkit 616e8db4c3b0 2022-03-10 17:48:09 -05:00
golang.org/x vendor: golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd 2022-03-17 13:59:03 +01:00
google.golang.org vendor: cloud.google.com/go v0.92.0, google.golang.org/api v0.54.0 2022-03-11 20:01:57 +01:00
gotest.tools/v3 vendor: gotest.tools/v3 v3.1.0 2022-03-01 17:02:53 +01:00
modules.txt vendor: golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd 2022-03-17 13:59:03 +01:00