rssh 2.3.4-4+deb8u2build0.16.04.1 source package in Ubuntu

Changelog

rssh (2.3.4-4+deb8u2build0.16.04.1) xenial-security; urgency=medium

  * fake sync from Debian

rssh (2.3.4-4+deb8u2) jessie-security; urgency=high

  * Non-maintainer upload by the LTS team.
  * Backport security fixes prepared by Debian's maintainer of rssh (rra).
  * Also reject rsync --daemon and --config command-line options, which
    can be used to run arbitrary commands.  Thanks, Nick Cleaton.
    (CVE-2019-3463)
  * Unset the HOME environment variable when running rsync to prevent popt
    (against which rsync is linked) from loading a ~/.popt configuration
    file, which can run arbitrary commands on the server or redefine
    command-line options to bypass argument checking.  Thanks, Nick
    Cleaton.  (CVE-2019-3464)
  * Do not stop checking the rsync command line at --, since this can be
    an argument to some other option and later arguments may still be
    interpreted as options.  In the few cases where one needs to rsync to
    files named things like --rsh, the client can use ./--rsh instead.
    Thanks, Nick Cleaton.

 -- Steve Beattie <email address hidden>  Thu, 07 Feb 2019 14:28:48 -0800

Upload details

Uploaded by:
Steve Beattie
Uploaded to:
Xenial
Original maintainer:
Russ Allbery
Architectures:
any
Section:
net
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
rssh_2.3.4.orig.tar.gz 110.7 KiB f30c6a760918a0ed39cf9e49a49a76cb309d7ef1c25a66e77a41e2b1d0b40cd9
rssh_2.3.4-4+deb8u2build0.16.04.1.debian.tar.xz 28.7 KiB 4759cee509772486638cf105bb839ad98fe16a43b745fc72fef5a924ea549a36
rssh_2.3.4-4+deb8u2build0.16.04.1.dsc 1.8 KiB 5bf4f89549b5fca2d1136b3d40ab97ddc77aa0f65af03fadde8d7511beb2d2c9

View changes file

Binary packages built by this source

rssh: Restricted shell allowing scp, sftp, cvs, svn, rsync or rdist

 rssh is a restricted shell, used as a login shell, that allows users to
 perform only scp, sftp, cvs, svnserve (Subversion), rdist, and/or rsync
 operations. It can also optionally chroot user logins into a restricted
 jail.

rssh-dbgsym: debug symbols for package rssh

 rssh is a restricted shell, used as a login shell, that allows users to
 perform only scp, sftp, cvs, svnserve (Subversion), rdist, and/or rsync
 operations. It can also optionally chroot user logins into a restricted
 jail.