Bug#349303: lsh-server: lshd leaks fd:s to user shells

2006-01-22 Thread Martin Schulze
Stefan Pfetzing wrote: > >Please let us know which version in sid will fix the problem. > > > >I've requested a CVE name and will provide it asap. > > lsh-utilis 2.0.1cdbs-4 includes a dpatch file in debian/patches which > fixes the problem. Please use CVE-2006-0353 for this vulnerability. Reg

Bug#349303: lsh-server: lshd leaks fd:s to user shells

2006-01-22 Thread Stefan Pfetzing
Hi Joey, Am 22.01.2006 um 09:52 schrieb Martin Schulze: Please let us know which version in sid will fix the problem. I've requested a CVE name and will provide it asap. lsh-utilis 2.0.1cdbs-4 includes a dpatch file in debian/patches which fixes the problem. bye Stefan -- http:

Bug#349303: lsh-server: lshd leaks fd:s to user shells

2006-01-22 Thread Martin Schulze
Stefan Pfetzing wrote: > Package: lsh-server > Version: 2.0.1cdbs-3 > Severity: grave > Tags: security > Tags: sarge > Tags: confirmed > Tags: pending > Justification: denial of service > > As reported by Niels Möller, the author of lsh-utils, a user is able to > access fd:s used by lsh. > > When

Bug#349303: lsh-server: lshd leaks fd:s to user shells

2006-01-21 Thread Stefan Pfetzing
Package: lsh-server Version: 2.0.1cdbs-3 Severity: grave Tags: security Tags: sarge Tags: confirmed Tags: pending Justification: denial of service As reported by Niels Möller, the author of lsh-utils, a user is able to access fd:s used by lsh. When logging in through lsh-server a user is able to