version 1.1, 2016/02/20 14:18:42 |
version 1.2, 2016/03/10 11:57:24 |
|
|
|
|
<ul> |
<ul> |
|
|
<li>None yet. |
<li id="001_sshd"> |
|
<font color="#009000"><strong>001: SECURITY FIX: March 10, 2016</strong></font> |
|
<i>All architectures</i><br> |
|
<a href="http://www.openssh.com/txt/x11fwd.adv"> |
|
Lack of credential sanitization allows injection of commands to xauth(1).</a> |
|
<br> |
|
Prevent this problem immediately by not using the "X11Forwarding" feature |
|
(which is disabled by default) |
|
<br> |
|
<a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/001_sshd.patch.sig"> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
|
|
</ul> |
</ul> |
|
|