Dit bericht is nog niet vertaald

[USN-566-1] OpenSSH vulnerability

Ubuntu Security Notice USN-566-1           January 09, 2008
openssh vulnerability
CVE-2007-4752
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
openssh-client 1:4.2p1-7ubuntu3.2
Ubuntu 6.10
openssh-client 1:4.3p2-5ubuntu1.1
Ubuntu 7.10
openssh-client 1:4.6p1-5ubuntu0.1
Ubuntu 7.04
openssh-client 1:4.3p2-8ubuntu1.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Jan Pechanec discovered that ssh would forward trusted X11 cookies when untrusted cookie generation failed. This could lead to unintended privileges being forwarded to a remote host.