=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata58.html,v retrieving revision 1.15 retrieving revision 1.16 diff -u -r1.15 -r1.16 --- www/errata58.html 2016/02/20 14:18:42 1.15 +++ www/errata58.html 2016/03/10 11:57:24 1.16 @@ -191,6 +191,19 @@ A source code patch exists which remedies this problem.

+

  • +011: SECURITY FIX: March 10, 2016All architectures
    + +Lack of credential sanitization allows injection of commands to xauth(1). +
    +Prevent this problem immediately by not using the "X11Forwarding" feature +(which is disabled by default) +
    + +A source code patch exists which remedies this problem. +

    +