=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata57.html,v retrieving revision 1.35 retrieving revision 1.36 diff -c -r1.35 -r1.36 *** www/errata57.html 2016/02/20 14:18:42 1.35 --- www/errata57.html 2016/03/10 11:57:24 1.36 *************** *** 335,340 **** --- 335,353 ---- A source code patch exists which remedies this problem.

+

  • + 023: SECURITY FIX: March 10, 2016 +   All architectures
    + + Lack of credential sanitization allows injection of commands to xauth(1). +
    + Prevent this problem immediately by not using the "X11Forwarding" feature + (which is disabled by default) +
    + + A source code patch exists which remedies this problem. +

    +