Summary: | net-misc/openssh <4.7_p1-r6 rc execution overrides ForceCommand restriction (CVE-2008-1657) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Robert Buchholz (RETIRED) <rbu> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | ||
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://secunia.com/advisories/29602/ | ||
Whiteboard: | A3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Robert Buchholz (RETIRED)
![]() if we could get a small diff for 4.7_p1, that would be best ... The patch is here: ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/001_openssh.patch openssh-4.7_p1-r6 in the tree then with that one fix, thanks openssh-4.9_p1 is also in the tree, but it's missing updated patches, so stabilizing that version would just make users'/admins' lives painful Arches, please test and mark stable: =net-misc/openssh-4.7_p1-r6 Target keywords : "alpha amd64 arm hppa ia64 m68k ppc ppc64 release s390 sh sparc x86" x86 stable amd64 stable alpha/ia64/sparc stable ppc64 stable Stable for HPPA. ppc stable request has been filed Fixed in release snapshot. GLSA 200804-03 Fixed for ~arch in 5.0_p1 |