openssh 1:6.9p1-2ubuntu0.2 source package in Ubuntu

Changelog

openssh (1:6.9p1-2ubuntu0.2) wily-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via environment files when
    UseLogin is configured
    - debian/patches/CVE-2015-8325.patch: ignore PAM environment vars when
      UseLogin is enabled in session.c.
    - CVE-2015-8325
  * SECURITY UPDATE: denial of service via cradted network traffic
    - debian/patches/CVE-2016-1907.patch: fix OOB read in packet code in
      packet.c.
    - CVE-2016-1907
  * SECURITY UPDATE: fallback from untrusted X11-forwarding to trusted
    - debian/patches/CVE-2016-1908-1.patch: use stack memory in
      clientloop.c.
    - debian/patches/CVE-2016-1908-2.patch: eliminate fallback in
      clientloop.c, clientloop.h, mux.c, ssh.c.
    - CVE-2016-1908
  * SECURITY UPDATE: shell-command restrictions bypass via crafted X11
    forwarding data
    - debian/patches/CVE-2016-3115.patch: sanitise characters destined for
      xauth in session.c.
    - CVE-2016-3115

 -- Marc Deslauriers <email address hidden>  Thu, 05 May 2016 07:54:01 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Wily
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssh_6.9p1.orig.tar.gz 1.4 MiB 6e074df538f357d440be6cf93dc581a21f22d39e236f217fcd8eacbb6c896cfe
openssh_6.9p1-2ubuntu0.2.debian.tar.xz 152.5 KiB b7a78962ae1af075b57710162320dac0700d5467ea3c366fe45b42d42100808d
openssh_6.9p1-2ubuntu0.2.dsc 2.8 KiB 22881beb6074fdced6de1711aee04ef9787e4ec2fb6e546a02dc92811c922ee6

View changes file

Binary packages built by this source

openssh-client: No summary available for openssh-client in ubuntu wily.

No description available for openssh-client in ubuntu wily.

openssh-client-dbgsym: No summary available for openssh-client-dbgsym in ubuntu wily.

No description available for openssh-client-dbgsym in ubuntu wily.

openssh-client-udeb: No summary available for openssh-client-udeb in ubuntu wily.

No description available for openssh-client-udeb in ubuntu wily.

openssh-client-udeb-dbgsym: No summary available for openssh-client-udeb-dbgsym in ubuntu wily.

No description available for openssh-client-udeb-dbgsym in ubuntu wily.

openssh-server: No summary available for openssh-server in ubuntu wily.

No description available for openssh-server in ubuntu wily.

openssh-server-dbgsym: No summary available for openssh-server-dbgsym in ubuntu wily.

No description available for openssh-server-dbgsym in ubuntu wily.

openssh-server-udeb: No summary available for openssh-server-udeb in ubuntu wily.

No description available for openssh-server-udeb in ubuntu wily.

openssh-server-udeb-dbgsym: No summary available for openssh-server-udeb-dbgsym in ubuntu wily.

No description available for openssh-server-udeb-dbgsym in ubuntu wily.

openssh-sftp-server: No summary available for openssh-sftp-server in ubuntu wily.

No description available for openssh-sftp-server in ubuntu wily.

openssh-sftp-server-dbgsym: No summary available for openssh-sftp-server-dbgsym in ubuntu wily.

No description available for openssh-sftp-server-dbgsym in ubuntu wily.

ssh: No summary available for ssh in ubuntu wily.

No description available for ssh in ubuntu wily.

ssh-askpass-gnome: No summary available for ssh-askpass-gnome in ubuntu wily.

No description available for ssh-askpass-gnome in ubuntu wily.

ssh-askpass-gnome-dbgsym: No summary available for ssh-askpass-gnome-dbgsym in ubuntu wily.

No description available for ssh-askpass-gnome-dbgsym in ubuntu wily.

ssh-krb5: No summary available for ssh-krb5 in ubuntu wily.

No description available for ssh-krb5 in ubuntu wily.