Format: 1.8 Date: Fri, 28 Mar 2014 18:04:41 +0000 Source: openssh Binary: openssh-client openssh-server openssh-sftp-server ssh ssh-krb5 ssh-askpass-gnome openssh-client-udeb openssh-server-udeb Architecture: i386 all i386_translations Version: 1:6.6p1-1 Distribution: trusty-proposed Urgency: medium Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Colin Watson Description: openssh-client - secure shell (SSH) client, for secure access to remote machines openssh-client-udeb - secure shell client for the Debian installer (udeb) openssh-server - secure shell (SSH) server, for secure access from remote machines openssh-server-udeb - secure shell server for the Debian installer (udeb) openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot ssh - secure shell client and server (metapackage) ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad ssh-krb5 - secure shell client and server (transitional package) Closes: 298138 341883 742308 742513 742541 Launchpad-Bugs-Fixed: 1244736 1298280 Changes: openssh (1:6.6p1-1) unstable; urgency=medium . [ Colin Watson ] * Apply various warning-suppression and regression-test fixes to gssapi.patch from Damien Miller. * New upstream release (http://www.openssh.com/txt/release-6.6, LP: #1298280): - CVE-2014-2532: sshd(8): when using environment passing with an sshd_config(5) AcceptEnv pattern with a wildcard, OpenSSH prior to 6.6 could be tricked into accepting any environment variable that contains the characters before the wildcard character. * Re-enable btmp logging, as its permissions were fixed a long time ago in response to #370050 (closes: #341883). * Change to "PermitRootLogin without-password" for new installations, and ask a debconf question when upgrading systems with "PermitRootLogin yes" from previous versions (closes: #298138). * Debconf translations: - Danish (thanks, Joe Hansen). - Portuguese (thanks, Américo Monteiro). - Russian (thanks, Yuri Kozlov; closes: #742308). - Swedish (thanks, Andreas Rönnquist). - Japanese (thanks, victory). - German (thanks, Stephan Beck; closes: #742541). - Italian (thanks, Beatrice Torracca). * Don't start ssh-agent from the Upstart user session job if something like Xsession has already done so (based on work by Bruno Vasselle; LP: #1244736). . [ Matthew Vernon ] * CVE-2014-2653: Fix failure to check SSHFP records if server presents a certificate (bug reported by me, patch by upstream's Damien Miller; thanks also to Mark Wooding for his help in fixing this) (Closes: #742513) Checksums-Sha1: 72faca15fb04706c025d6860d00f13d582b08675 578614 openssh-client_6.6p1-1_i386.deb 838db5036507fc5e62e834f6c3d364b898869d7f 322910 openssh-server_6.6p1-1_i386.deb 033c19b554e78fd3b912d6d0e426b98135711f12 35530 openssh-sftp-server_6.6p1-1_i386.deb 54fdcb6569903fe750ef9d167060d2288d0c422e 1104 ssh_6.6p1-1_all.deb 1340812abb426e2adb3313a5a47f1102a495926d 7910 ssh-krb5_6.6p1-1_all.deb e9650dc536195756ee412008bdeed72d764154b9 14370 ssh-askpass-gnome_6.6p1-1_i386.deb 2d29b5717c76d5e93b9038b8454e295dc785449f 252934 openssh-client-udeb_6.6p1-1_i386.udeb bb5648b723659e6f9f576d7284d25000ef40c35a 282086 openssh-server-udeb_6.6p1-1_i386.udeb ac4bd12c48d22821100363cc5490d5328a7319b9 5103 openssh_6.6p1-1_i386_translations.tar.gz Checksums-Sha256: 1be03fb5101c31c7f6e917fca0e2c098ca92e34e6d9a4a388c49255b5d294a4e 578614 openssh-client_6.6p1-1_i386.deb e3ecc5f24038ebd22dbf490057f3dcc7e66109051aa0abe430fb124de2ea61b7 322910 openssh-server_6.6p1-1_i386.deb 3d0837d60bdb0b25be714dbbbc05cd5567dcb8dc6572519afa5033c3a94f4b3b 35530 openssh-sftp-server_6.6p1-1_i386.deb a1865d6c4d77e4115d371d46f615456f2948b3a3ce5c2337c702f49e7683e04a 1104 ssh_6.6p1-1_all.deb 581a312e8f2c49ca1b5b5a56ab56c7a0500acf2b7741164008dffbbb853ad4ec 7910 ssh-krb5_6.6p1-1_all.deb 196c9a11c6a6ff882cdfafeaef04c151ef0b1eec21fcc5d6d1b9387a0c47edf7 14370 ssh-askpass-gnome_6.6p1-1_i386.deb f0113faea5207b80b213e774f2c5fa35025581b0e91a7f0ca75d38dbb151cc04 252934 openssh-client-udeb_6.6p1-1_i386.udeb 758451c880222c8edc8a8f8c738beaa33ea799097a7155877111448560c4a596 282086 openssh-server-udeb_6.6p1-1_i386.udeb ef07ed2f086a0cd583fd1fb04ed3695d36903be42ab598ad10048d081581ec8f 5103 openssh_6.6p1-1_i386_translations.tar.gz Files: b4e81a0fcb9e5f0bbb58894ae985dffe 578614 net standard openssh-client_6.6p1-1_i386.deb 66e3fc74f9ef00a919c926d63fea21ee 322910 net optional openssh-server_6.6p1-1_i386.deb b3f807790aec7e649c1211fa6386ce90 35530 net optional openssh-sftp-server_6.6p1-1_i386.deb e3184a658c7b12c07b117c88bc6bb76b 1104 net extra ssh_6.6p1-1_all.deb 6643078ee6040e0eee197bc8e0eded2a 7910 oldlibs extra ssh-krb5_6.6p1-1_all.deb d4c0b991e4441d890051b30890bb7d6d 14370 gnome optional ssh-askpass-gnome_6.6p1-1_i386.deb bc787f2a6a2c01e570795d1eb2667602 252934 debian-installer optional openssh-client-udeb_6.6p1-1_i386.udeb f34966b3b4678322fe931a9706846d29 282086 debian-installer optional openssh-server-udeb_6.6p1-1_i386.udeb 7aff82deefbfc054722f7d32970eb1e8 5103 raw-translations - openssh_6.6p1-1_i386_translations.tar.gz Package-Type: udeb