This is the mail archive of the
cygwin-apps
mailing list for the Cygwin project.
RE: [SECURITY] p7zip: CVE-2015-1038
- From: Tony Kelman <tony at kelman dot net>
- To: "cygwin-apps at cygwin dot com" <cygwin-apps at cygwin dot com>
- Date: Mon, 8 Feb 2016 17:42:32 -0800
- Subject: RE: [SECURITY] p7zip: CVE-2015-1038
- Authentication-results: sourceware.org; auth=none
- References: <56AB9A3F dot 3040808 at cygwin dot com> <BAY169-W135C2459F190107A746FE76A7DB0 at phx dot gbl> <BAY169-W401D7F793D3E837DBF61F5A7DC0 at phx dot gbl> <BAY169-W408B5913ECB16EC67C8CD4A7DC0 at phx dot gbl>,<20160208135409 dot GI27646 at calimero dot vinschen dot de>
>> Tony@LAPTOP-O230JCFF ~/github/cygwin-p7zip
>> $ cygport p7zip-15.09-2.cygport upload
>>>>> Uploading p7zip-15.09-2.x86_64
>>>>> Running lftp sftp://cygwin@cygwin.com
>> Password:
>> cd: Fatal error: Host key verification failed
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>
> The host key you stored for sourceware isn't the right one for some
> reason. Remove it with ssh-keygen -R and check for correctness when
> you connect again, see the fingerprints at
> https://sourceware.org/cygwin-apps/package-upload.html
Thanks for the help Corinna.
I don't have anything for sourceware or cygwin.com in
~/.ssh/known_hosts, should I?
-Tony