[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1064898: /usr/bin/sshd: mktemp - literal X-s in /tmp directory names



hi Colin,

On 2024-03-03 20:27, Colin Watson wrote:
On Tue, Feb 27, 2024 at 12:56:47PM +0100, Csillag Tamas wrote:
   * What led up to the situation?
After upgrading to debian 12 I am seeing directories in /tmp like:
     ssh-XXXXXXnOKqkt, ssh-XXXXXXtGmfLV
   * What was the outcome of this action?
   * What outcome did you expect instead?
     These directories are created by sshd.
     In oldstable and OpenBSD the directories are as expected:
     ssh-LwxtSMoGSV, ssh-JPcQMaBN6s

     The regression might be only in openssh-portable?

As there are still 6 variable characters this might not be easily exploitable
security-wise and it used to be 10 just as in OpenBSD current.

This is the same as https://bugs.debian.org/1001186; it's fixed for the
next development release, but not yet for bookworm.

Since this doesn't appear to be immediately serious, my inclination is
to queue this up to fix along with the next bookworm openssh security
update (whenever that might be), but not to trouble the security team
with it right away.  Does that sound reasonable?

Okay that sounds reasonable to me.
It would be nice to have it in one of the next point releases if it is not too much trouble.

Regards,
 Tamás


Reply to: