Re: "unprivileged users may hijack forwarded X connections"

2008-04-29 Thread David Ehle
Nico, Thank you very much for the link! Is there any way to find out what the ETA on release would be? This is one of the items checked by my lab's security scanning system, so I would like to get it addressed quickly, but prefer to do it via debian package rather than manual patch. -- Da

Re: "unprivileged users may hijack forwarded X connections"

2008-04-29 Thread Nico Golde
Hi David, * David Ehle <[EMAIL PROTECTED]> [2008-04-29 21:06]: [...] > It looks like it hs been handled for testing/unstable but its unclear if this > fix has been applied to version currently in etch (OpenSSH_4.3p2 Debian-9) > and > the security repository. > > Does anyone know if this has be

"unprivileged users may hijack forwarded X connections"

2008-04-29 Thread David Ehle
Hello, I was curious what the status of a fix for the etch version of the bug would be: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463011 ssh: unprivileged users may hijack forwarded X connections by listening on port 6010 Severity: grave; Tags: security, upstream; Found in versions op