Bug#810984: openssh-client: CVE-2016-0777

2016-01-14 Thread Christoph Anton Mitterer
On Thu, 2016-01-14 at 15:03 +, Colin Watson wrote: > Yes, I do.  Upload coming soon. Great work :-) As usually the security team and maintainers are pretty fast in Debian... if now there wouldn't be easy ways for blocking attacks against secure APT, one could really feel pretty safe :) Cheers

Bug#810984: openssh-client: CVE-2016-0777

2016-01-14 Thread Christoph Anton Mitterer
On Thu, 2016-01-14 at 16:01 +0100, Yves-Alexis Perez wrote: > Thanks for the report, yes we're aware of it. The announcement doesn't read *that* extremely bad (well depends a bit on whether one connects to untrusted systems), though,... thus maybe the severity of this can be lowered. OTOH, since it

Bug#810984: openssh-client: CVE-2016-0777

2016-01-14 Thread Colin Watson
On Thu, Jan 14, 2016 at 03:49:40PM +0100, Christoph Anton Mitterer wrote: > You probably know about this already, but just in case not: > https://lists.mindrot.org/pipermail/openssh-unix-dev/2016-January/034679.html Yes, I do. Upload coming soon. -- Colin Watson

Bug#810984: openssh-client: CVE-2016-0777

2016-01-14 Thread Thijs Kinkhorst
On Thu, January 14, 2016 15:49, Christoph Anton Mitterer wrote: > You probably know about this already, but just in case not: > https://lists.mindrot.org/pipermail/openssh-unix-dev/2016-January/034679.html Thanks for reporting. The security team is indeed aware and a DSA is in preparation. Cheers

Bug#810984: openssh-client: CVE-2016-0777

2016-01-14 Thread Yves-Alexis Perez
On jeu., 2016-01-14 at 15:49 +0100, Christoph Anton Mitterer wrote: > Hey. > > You probably know about this already, but just in case not: > https://lists.mindrot.org/pipermail/openssh-unix-dev/2016-January/034679.htm > l Thanks for the report, yes we're aware of it. Regards, -- Yves-Alexis s

Bug#810984: openssh-client: CVE-2016-0777

2016-01-14 Thread Christoph Anton Mitterer
Package: openssh-client Version: 1:7.1p1-6 Severity: critical Tags: security Justification: root security hole Hey. You probably know about this already, but just in case not: https://lists.mindrot.org/pipermail/openssh-unix-dev/2016-January/034679.html Cheers, Chris. -- System Information: