rssh 2.3.4-4+deb8u2build0.14.04.1 source package in Ubuntu
Changelog
rssh (2.3.4-4+deb8u2build0.14.04.1) trusty-security; urgency=medium * fake sync from Debian rssh (2.3.4-4+deb8u2) jessie-security; urgency=high * Non-maintainer upload by the LTS team. * Backport security fixes prepared by Debian's maintainer of rssh (rra). * Also reject rsync --daemon and --config command-line options, which can be used to run arbitrary commands. Thanks, Nick Cleaton. (CVE-2019-3463) * Unset the HOME environment variable when running rsync to prevent popt (against which rsync is linked) from loading a ~/.popt configuration file, which can run arbitrary commands on the server or redefine command-line options to bypass argument checking. Thanks, Nick Cleaton. (CVE-2019-3464) * Do not stop checking the rsync command line at --, since this can be an argument to some other option and later arguments may still be interpreted as options. In the few cases where one needs to rsync to files named things like --rsh, the client can use ./--rsh instead. Thanks, Nick Cleaton. -- Steve Beattie <email address hidden> Thu, 07 Feb 2019 14:18:02 -0800
Upload details
- Uploaded by:
- Steve Beattie
- Uploaded to:
- Trusty
- Original maintainer:
- Russ Allbery
- Architectures:
- any
- Section:
- net
- Urgency:
- Very Urgent
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
rssh_2.3.4.orig.tar.gz | 110.7 KiB | f30c6a760918a0ed39cf9e49a49a76cb309d7ef1c25a66e77a41e2b1d0b40cd9 |
rssh_2.3.4-4+deb8u2build0.14.04.1.debian.tar.xz | 28.7 KiB | d9c19309ce6738c52924f682414d4f557aa14626a005200e9629a66504effa4c |
rssh_2.3.4-4+deb8u2build0.14.04.1.dsc | 1.8 KiB | eb20c573e9d170d23376d88d7f54d7c6bc112e5752376e01e4e28069adbcb9ac |
Available diffs
Binary packages built by this source
- rssh: Restricted shell allowing scp, sftp, cvs, svn, rsync or rdist
rssh is a restricted shell, used as a login shell, that allows users to
perform only scp, sftp, cvs, svnserve (Subversion), rdist, and/or rsync
operations. It can also optionally chroot user logins into a restricted
jail.
- rssh-dbgsym: debug symbols for package rssh
rssh is a restricted shell, used as a login shell, that allows users to
perform only scp, sftp, cvs, svnserve (Subversion), rdist, and/or rsync
operations. It can also optionally chroot user logins into a restricted
jail.