C'est marrant pour un même correctif, on passe d'un niveau d'urgence haut chez Debian :
openssh (1:6.0p1-4+deb7u3) wheezy-security; urgency=high
* Non-maintainer upload by the Security Team.
* Disable roaming in openssh client: roaming code is vulnerable to an
information leak (CVE-2016-0777) and heap-based buffer overflow
(CVE-2016-0778).
-- Yves-Alexis Perez <corsac@debian.org> 2016年1月13日 22:35:39 +0100
À un niveau d'urgence moyen chez Ubuntu :
openssh (1:6.6p1-2ubuntu2.4) trusty-security; urgency=medium
* SECURITY UPDATE: information leak and overflow in roaming support
- debian/patches/CVE-2016-077x.patch: completely disable roaming option
in readconf.c.
- CVE-2016-0777
- CVE-2016-0778
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> 2016年1月13日 10:48:19 -0500
[^] # Re: Déjà dans Debian
Posté par Bruno Ethvignot (site web personnel) . En réponse au journal OpenSSH, UseRoaming no. Évalué à 4.
C'est marrant pour un même correctif, on passe d'un niveau d'urgence haut chez Debian :
À un niveau d'urgence moyen chez Ubuntu :