[Bug 227322] Re: [openssh] [CVE-2008-1657] possibility to bypass global ForceCommand directive

2008-10-01 Thread Kees Cook
Did not apply to Dapper or Feisty. Already fixed in Hardy and Intrepid. USN published for Gutsy: http://www.ubuntu.com/usn/usn-649-1 ** Changed in: openssh (Ubuntu Hardy) Assignee: (unassigned) = Colin Watson (kamion) Status: New = Fix Released ** Changed in: openssh (Ubuntu Gutsy)

[Bug 227322] Re: [openssh] [CVE-2008-1657] possibility to bypass global ForceCommand directive

2008-05-06 Thread Colin Watson
Already fixed in Hardy/Intrepid and backported to earlier releases. Please look at the changelog as well as just the version number! openssh (1:4.7p1-8) unstable; urgency=high * Fill in CVE identifier for security vulnerability fixed in 1:4.7p1-5. * Rename KeepAlive to TCPKeepAlive in

[Bug 227322] Re: [openssh] [CVE-2008-1657] possibility to bypass global ForceCommand directive

2008-05-06 Thread Colin Watson
Already fixed in Hardy/Intrepid and backported to earlier releases. Please look at the changelog as well as just the version number! openssh (1:4.7p1-8) unstable; urgency=high * Fill in CVE identifier for security vulnerability fixed in 1:4.7p1-5. * Rename KeepAlive to TCPKeepAlive in

[Bug 227322] Re: [openssh] [CVE-2008-1657] possibility to bypass global ForceCommand directive

2008-05-06 Thread hk47
So many things to check... Okay. Just checked at packages.ubuntu.com. Regarding CVE-2008-1657 - there is no USN - nothing is mentioned in the changelogs of the corresponding packages for Dapper/Feisty/Gutsy The last update on those packages are from Kees on April 1st for CVE-2008-1483 as I see