• [^] # Re: Déjà dans Debian

    Posté par (site web personnel) . En réponse au journal OpenSSH, UseRoaming no. Évalué à 4.

    C'est marrant pour un même correctif, on passe d'un niveau d'urgence haut chez Debian :

    openssh (1:6.0p1-4+deb7u3) wheezy-security; urgency=high
     * Non-maintainer upload by the Security Team.
     * Disable roaming in openssh client: roaming code is vulnerable to an
     information leak (CVE-2016-0777) and heap-based buffer overflow
     (CVE-2016-0778).
     -- Yves-Alexis Perez <corsac@debian.org> 2016年1月13日 22:35:39 +0100
    

    À un niveau d'urgence moyen chez Ubuntu :

    openssh (1:6.6p1-2ubuntu2.4) trusty-security; urgency=medium
     * SECURITY UPDATE: information leak and overflow in roaming support
     - debian/patches/CVE-2016-077x.patch: completely disable roaming option
     in readconf.c.
     - CVE-2016-0777
     - CVE-2016-0778
     -- Marc Deslauriers <marc.deslauriers@ubuntu.com> 2016年1月13日 10:48:19 -0500