rssh 2.3.4-9 source package in Debian
Changelog
rssh (2.3.4-9) unstable; urgency=high [ Russ Allbery ] * Validate the allowed scp command line and only permit the flags used in server mode and only a single argument, to attempt to prevent use of ssh options to run arbitrary code on the server. This will break scp -3 to a system running rssh, which seems like an acceptable loss. (Closes: #919623, CVE-2019-1000018) * Tighten validation of the rsync command line to require --server be the first argument, which should prevent initiation of an outbound rsync command from the server, which in turn might allow execution of arbitrary code via ssh configuration similar to scp. * Add validation of the server command line after chroot when chroot is enabled. Prior to this change, dangerous argument filtering was not done when chroot was configured, allowing remote code execution inside the chroot in some configurations via the previous two bugs and via the mechanisms in CVE-2012-2251 and CVE-2012-2252. * Document that the cvs server-side dangerous option filtering is probably insufficient and should not be considered secure. * Remove ancient upgrade support in debian/postinst. * Remove debian/source/options, which was forcing compression to xz (now the default). * Update to debhelper compatibility level V12. * Update standards version to 4.3.0 (no changes required). [ Ondřej Nový ] * d/watch: Use https protocol -- Russ Allbery <email address hidden> Mon, 28 Jan 2019 21:03:59 -0800
Upload details
- Uploaded by:
- Russ Allbery
- Uploaded to:
- Sid
- Original maintainer:
- Russ Allbery
- Architectures:
- any
- Section:
- net
- Urgency:
- Very Urgent
See full publishing history Publishing
Series | Published | Component | Section |
---|
Builds
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
rssh_2.3.4-9.dsc | 1.5 KiB | 59a60a8c4c703752afd349e56a5acf848f4e6a8ba9a7de14b25b8522a716711e |
rssh_2.3.4.orig.tar.gz | 110.7 KiB | f30c6a760918a0ed39cf9e49a49a76cb309d7ef1c25a66e77a41e2b1d0b40cd9 |
rssh_2.3.4-9.debian.tar.xz | 29.0 KiB | aae025b0d9b2d335ad140ecb872b97ec162cd26aae81aaf979d97478db9a4a24 |
Available diffs
- diff from 2.3.4-8 to 2.3.4-9 (5.8 KiB)
No changes file available.