LWN.net Logo

Fedora alert FEDORA-2008-1728 (scponly)

From:  updates@fedoraproject.org
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora 7 Update: scponly-4.6-10.fc7
Date:  Fri, 15 Feb 2008 19:14:48 -0700
Message-ID:  <200802160214.m1G2ENbF028131@bastion.fedora.phx.redhat.com>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-1728 2008-02-15 21:19:11 -------------------------------------------------------------------------------- Name : scponly Product : Fedora 7 Version : 4.6 Release : 10.fc7 URL : http://sublimation.org/scponly/ Summary : Restricted shell for ssh based file services Description : scponly is an alternative 'shell' for system administrators who would like to provide access to remote users to both read and write local files without providing any remote execution priviledges. Functionally, it is best described as a wrapper to the "tried and true" ssh suite of applications. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 13 2008 Tomas Hoger <thoger@redhat.com> - 4.6-10 - Add patch to prevent restriction bypass using OpenSSH's scp options -F and -o (CVE-2007-6415, #426072) * Mon Feb 11 2008 Warren Togami <wtogami@redhat.com> - 4.6-9 - rebuild with gcc-4.3 * Tue Dec 11 2007 Toshio Kuratomi <a.badger@gmail.com> - 4.6-8 - Disable rsync support due to security concerns: RH BZ#418201 * Tue Aug 21 2007 Warren Togami <wtogami@redhat.com> - 4.6-7 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #418201 - CVE-2007-6350 scponly: rsync, svn and unison support may be dangerous https://bugzilla.redhat.com/show_bug.cgi?id=418201 [ 2 ] Bug #426072 - CVE-2007-6415 scponly: scp restriction bypass https://bugzilla.redhat.com/show_bug.cgi?id=426072 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update scponly' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2009, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds