Actually, guty is affected-- the aforementioned changelog entry is for
CVE-2007-6350. CVE-2007-6415 was fixed in Debian in 4.6-1.2.

scponly (4.6-1.2) unstable; urgency=high
  
  * Non-maintainer upload by the Security Team
  * scp: -o and -F options are dangerous (CVE-2007-6415).


** CVE added: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6350

** Changed in: scponly (Ubuntu Gutsy)
       Status: New => Confirmed

-- 
CVE-2007-6415 - scponly allows remote command execution
https://bugs.launchpad.net/bugs/249593
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to