moby/vendor/golang.org/x/crypto
Sebastiaan van Stijn c22fc41ddf
vendor: golang.org/x/crypto v0.17.0
update the package, which contains a fix in the ssh package.

full diff: https://github.com/golang/crypto/compare/v0.16.0...v0.17.0

from the security mailing:

> Hello gophers,
>
> Version v0.17.0 of golang.org/x/crypto fixes a protocol weakness in the
> golang.org/x/crypto/ssh package that allowed a MITM attacker to compromise
> the integrity of the secure channel before it was established, allowing
> them to prevent transmission of a number of messages immediately after
> the secure channel was established without either side being aware.
>
> The impact of this attack is relatively limited, as it does not compromise
> confidentiality of the channel. Notably this attack would allow an attacker
> to prevent the transmission of the SSH2_MSG_EXT_INFO message, disabling a
> handful of newer security features.
>
> This protocol weakness was also fixed in OpenSSH 9.6.
>
> Thanks to Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk from Ruhr
> University Bochum for reporting this issue.
>
> This is CVE-2023-48795 and Go issue https://go.dev/issue/64784.
>
> Cheers,
> Roland on behalf of the Go team

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2023-12-19 00:30:17 +01:00
..
blowfish vendor: github.com/moby/buildkit v0.8.0-rc2 2020-11-19 10:31:35 +01:00
chacha20 vendor: golang.org/x/crypto v0.16.0 2023-12-18 13:39:50 +01:00
chacha20poly1305 vendor: golang.org/x/crypto v0.16.0 2023-12-18 13:39:50 +01:00
cryptobyte vendor: golang.org/x/crypto v0.16.0 2023-12-18 13:39:50 +01:00
curve25519 vendor: golang.org/x/crypto v0.16.0 2023-12-18 13:39:50 +01:00
ed25519 vendor: golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd 2022-03-17 13:59:03 +01:00
hkdf vendor: golang.org/x/crypto v0.16.0 2023-12-18 13:39:50 +01:00
internal vendor: golang.org/x/crypto v0.16.0 2023-12-18 13:39:50 +01:00
nacl vendor: golang.org/x/crypto v0.14.0 2023-10-11 18:57:10 +02:00
ocsp vendor: golang.org/x/crypto v0.1.0 2022-11-15 13:43:28 +01:00
pbkdf2 vendor: golang.org/x/crypto v0.1.0 2022-11-15 13:43:28 +01:00
pkcs12 vendor: golang.org/x/crypto v0.2.0 2022-11-25 17:57:16 +01:00
salsa20/salsa vendor: golang.org/x/crypto v0.16.0 2023-12-18 13:39:50 +01:00
ssh vendor: golang.org/x/crypto v0.17.0 2023-12-19 00:30:17 +01:00
LICENSE project: use vndr for vendoring 2016-11-03 15:31:46 -07:00
PATENTS project: use vndr for vendoring 2016-11-03 15:31:46 -07:00