[BACK]Return to errata43.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata43.html between version 1.1 and 1.2

version 1.1, 2008/03/09 21:05:00 version 1.2, 2008/03/31 01:40:47
Line 83 
Line 83 
   
 <ul>  <ul>
   
 <li>None yet.  <li><a name="001_openssh"></a>
   <font color="#009000"><strong>001: SECURITY FIX: March 30, 2008</strong></font> &nbsp; <i>All architectures</i><br>
   sshd(8) would execute ~/.ssh/rc even when a sshd_config(5) <em>ForceCommand</em>
   directive was in effect, allowing users with write access to this file to
   execute arbitrary commands. This behaviour was documented, but was an unsafe
   default and an extra hassle for administrators.<br>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/001_openssh.patch">
   A source code patch exists which remedies this problem</a>.<br>
   <p>
   
 </ul>  </ul>
   

Legend:
Removed from v.1.1  
changed lines
  Added in v.1.2