Commit Graph

27 Commits

Author SHA1 Message Date
Ed Maste dc9e8d9c84 Apply commit 3d896c15 from openssh-portable:
upstream: when checking that filenames sent by the server side

match what the client requested, be prepared to handle shell-style brace
alternations, e.g. "{foo,bar}".

"looks good to me" millert@ + in snaps for the last week courtesy
deraadt@

OpenBSD-Commit-ID: 3b1ce7639b0b25b2248e3a30f561a548f6815f3e

Discussed with:	des
2019-03-27 14:07:09 +00:00
Dag-Erling Smørgrav 8cb908a5b4 Re-apply scp filename matching fix. 2019-02-05 15:05:22 +00:00
Dag-Erling Smørgrav d18f6dc96d Vendor import of OpenSSH 7.9p1. 2019-02-05 15:03:53 +00:00
Dag-Erling Smørgrav 85f19ec0ec Merge upstream 2c21b75a7be6ebdcbceaebb43157c48dbb36f3d8:
| scp: add -T to usage();
|
| OpenBSD-Commit-ID: a7ae14d9436c64e1bd05022329187ea3a0ce1899
2019-02-05 08:10:36 +00:00
Dag-Erling Smørgrav e329cc28ba Merge upstream 391ffc4b9d31fa1f4ad566499fef9176ff8a07dc:
| remote->local directory copies satisfy the wildcard specified by the user.
|
| This checking provides some protection against a malicious server
| sending unexpected filenames, but it comes at a risk of rejecting wanted
| files due to differences between client and server wildcard expansion rules.
|
| For this reason, this also adds a new -T flag to disable the check.
|
| reported by Harry Sintonen
| fix approach suggested by markus@;
| has been in snaps for ~1wk courtesy deraadt@
|
| OpenBSD-Commit-ID: 00f44b50d2be8e321973f3c6d014260f8f7a8eda
2019-02-05 08:07:56 +00:00
Dag-Erling Smørgrav d46065df2d Vendor import of OpenSSH 7.8p1. 2018-08-28 10:47:58 +00:00
Dag-Erling Smørgrav c8a2bf1462 Vendor import of OpenSSH 7.7p1. 2018-05-06 12:27:04 +00:00
Dag-Erling Smørgrav 20adc8f2a9 Vendor import of OpenSSH 7.6p1. 2018-05-06 12:24:45 +00:00
Dag-Erling Smørgrav 19ca85510b Vendor import of OpenSSH 7.4p1. 2017-01-31 12:33:47 +00:00
Dag-Erling Smørgrav ab4ec008e7 Vendor import of OpenSSH 7.3p1. 2017-01-31 12:29:48 +00:00
Dag-Erling Smørgrav ff4b04e0d6 Vendor import of OpenSSH 7.2p1. 2016-03-10 20:10:25 +00:00
Dag-Erling Smørgrav b5a1b3a82d Vendor import of OpenSSH 6.9p1. 2015-07-02 13:18:50 +00:00
Dag-Erling Smørgrav c1e0861503 Vendor import of OpenSSH 6.8p1. 2015-07-02 13:15:34 +00:00
Dag-Erling Smørgrav c0bbca73c6 Vendor import of OpenSSH 6.7p1. 2015-01-05 16:09:55 +00:00
Dag-Erling Smørgrav 02d4c2ac3d Vendor import of OpenSSH 6.5p1. 2014-01-30 10:56:49 +00:00
Dag-Erling Smørgrav 0dddc34c88 Vendor import of OpenSSH 6.3p1 2013-09-18 17:27:38 +00:00
Dag-Erling Smørgrav 9b81c12876 Vendor import of OpenSSH 6.2p1. 2013-03-22 11:19:48 +00:00
Dag-Erling Smørgrav 2e97a36905 Vendor import of OpenSSH 6.0p1. 2012-08-29 15:46:01 +00:00
Dag-Erling Smørgrav 9f6de2d748 Vendor import of OpenSSH 5.7p1 2011-02-17 11:47:40 +00:00
Dag-Erling Smørgrav 3a927e69c3 Vendor import of OpenSSH 5.6p1 2010-11-08 10:45:44 +00:00
Dag-Erling Smørgrav 6d4f2dd11a Vendor import of OpenSSH 5.4p1 2010-03-08 11:19:52 +00:00
Dag-Erling Smørgrav 9ab1052dcd Vendor import of OpenSSH 5.2p1 2009-02-24 18:49:27 +00:00
Dag-Erling Smørgrav 5521539314 Vendor import of OpenSSH 5.1p1 2008-07-23 09:33:08 +00:00
Dag-Erling Smørgrav ad22e48f1a Vendor import of OpenSSH 4.9p1 for posterity's sake 2008-07-23 09:28:49 +00:00
Dag-Erling Smørgrav 490bfaade9 Vendor import of OpenSSH 4.7p1 for posterity's sake 2008-07-23 09:23:42 +00:00
Dag-Erling Smørgrav 24cf82b14a Vendor import of OpenSSH 4.6p1 for posterity's sake 2008-07-23 09:15:38 +00:00
Dag-Erling Smørgrav e3ae3b098d Properly flatten openssh/dist. 2008-07-22 19:01:18 +00:00