Format: 1.8 Date: Fri, 28 Mar 2014 18:04:41 +0000 Source: openssh Binary: openssh-client openssh-server openssh-sftp-server ssh ssh-krb5 ssh-askpass-gnome openssh-client-udeb openssh-server-udeb Architecture: armhf armhf_translations Version: 1:6.6p1-1 Distribution: trusty-proposed Urgency: medium Maintainer: Ubuntu/armhf Build Daemon Changed-By: Colin Watson Description: openssh-client - secure shell (SSH) client, for secure access to remote machines openssh-client-udeb - secure shell client for the Debian installer (udeb) openssh-server - secure shell (SSH) server, for secure access from remote machines openssh-server-udeb - secure shell server for the Debian installer (udeb) openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot ssh - secure shell client and server (metapackage) ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad ssh-krb5 - secure shell client and server (transitional package) Closes: 298138 341883 742308 742513 742541 Launchpad-Bugs-Fixed: 1244736 1298280 Changes: openssh (1:6.6p1-1) unstable; urgency=medium . [ Colin Watson ] * Apply various warning-suppression and regression-test fixes to gssapi.patch from Damien Miller. * New upstream release (http://www.openssh.com/txt/release-6.6, LP: #1298280): - CVE-2014-2532: sshd(8): when using environment passing with an sshd_config(5) AcceptEnv pattern with a wildcard, OpenSSH prior to 6.6 could be tricked into accepting any environment variable that contains the characters before the wildcard character. * Re-enable btmp logging, as its permissions were fixed a long time ago in response to #370050 (closes: #341883). * Change to "PermitRootLogin without-password" for new installations, and ask a debconf question when upgrading systems with "PermitRootLogin yes" from previous versions (closes: #298138). * Debconf translations: - Danish (thanks, Joe Hansen). - Portuguese (thanks, Américo Monteiro). - Russian (thanks, Yuri Kozlov; closes: #742308). - Swedish (thanks, Andreas Rönnquist). - Japanese (thanks, victory). - German (thanks, Stephan Beck; closes: #742541). - Italian (thanks, Beatrice Torracca). * Don't start ssh-agent from the Upstart user session job if something like Xsession has already done so (based on work by Bruno Vasselle; LP: #1244736). . [ Matthew Vernon ] * CVE-2014-2653: Fix failure to check SSHFP records if server presents a certificate (bug reported by me, patch by upstream's Damien Miller; thanks also to Mark Wooding for his help in fixing this) (Closes: #742513) Checksums-Sha1: f6a375513774e26013a32f6097e1145a9038ac27 525230 openssh-client_6.6p1-1_armhf.deb 60d079ef754d91e3d21703b067a691dbd63e92f2 314578 openssh-server_6.6p1-1_armhf.deb 231688bc3c52a36a353fac28d16f5d4c15512c27 30572 openssh-sftp-server_6.6p1-1_armhf.deb 1816c2c7a4ce739ec08ba851c0105a2afd8a9333 14008 ssh-askpass-gnome_6.6p1-1_armhf.deb 37455e8a75692a01afd70d62606b97ae0626a74e 234356 openssh-client-udeb_6.6p1-1_armhf.udeb 692f81f41cbaf7817d9a73b209bfe6c5f883d36f 259388 openssh-server-udeb_6.6p1-1_armhf.udeb daf5d44c13ff4365724ec2f51a157ddf31fbdd7d 5089 openssh_6.6p1-1_armhf_translations.tar.gz Checksums-Sha256: 74936264c878ac898d2d3b4b1884e4c56508ad1fc3ad05e3b43aa4d58a5ca37e 525230 openssh-client_6.6p1-1_armhf.deb 4c31a1fc50bbe2ef368c12cd81ca38027a2a6a60e7468aa073b8badca8679364 314578 openssh-server_6.6p1-1_armhf.deb ced8935a82fc731369a4766fe6161fcaac222be580bf688aee4ba9f14123971d 30572 openssh-sftp-server_6.6p1-1_armhf.deb 408b5781e2be368317d31dbf1133e25a288ebb8ec8c30a05b74a964007689217 14008 ssh-askpass-gnome_6.6p1-1_armhf.deb a2dadf9792d12425ce894ffe9847945d6e0f5753352edf31c0b803bc5ff2d47f 234356 openssh-client-udeb_6.6p1-1_armhf.udeb 721f55692ddc219eef790768850a6e4e21d408726edfbc053d2e10fd48f4e05d 259388 openssh-server-udeb_6.6p1-1_armhf.udeb 76e3d9141dbc83b2d1626e15a7bff4798b58b5f358fedd8877c5d17280e8cc03 5089 openssh_6.6p1-1_armhf_translations.tar.gz Files: 31b44841d396e7ff25c885269246fea2 525230 net standard openssh-client_6.6p1-1_armhf.deb a9f59dc66333afcb7874c8dbee9e8ccb 314578 net optional openssh-server_6.6p1-1_armhf.deb 56b446161ca606cfd80cb3addf7693b3 30572 net optional openssh-sftp-server_6.6p1-1_armhf.deb 5aae88939a909bebcdcf6f23a2e50b61 14008 gnome optional ssh-askpass-gnome_6.6p1-1_armhf.deb 8013c0d174bfbc163f7cbfc40cd69334 234356 debian-installer optional openssh-client-udeb_6.6p1-1_armhf.udeb 4ca9e5c69a042006daec053ef9cd0ee5 259388 debian-installer optional openssh-server-udeb_6.6p1-1_armhf.udeb 6d25aba5feecca70e481fcb3ecc99c96 5089 raw-translations - openssh_6.6p1-1_armhf_translations.tar.gz Package-Type: udeb