=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata58.html,v retrieving revision 1.12 retrieving revision 1.13 diff -c -r1.12 -r1.13 *** www/errata58.html 2015/12/06 11:54:58 1.12 --- www/errata58.html 2016/01/14 14:51:54 1.13 *************** *** 177,182 **** --- 177,195 ---- A source code patch exists which remedies this problem.

+

  • + 010: SECURITY FIX: January 14, 2016 +   All architectures
    + Experimental roaming code in the ssh client could be tricked by a hostile sshd + server, potentially leaking key material. CVE-2016-077 and CVE-0216-078. +
    + Prevent this problem immediately by adding the line "UseRoaming no" to + /etc/ssh/ssh_config. +
    + + A source code patch exists which remedies this problem. +

    +