Debian Security Advisory

DLA-1660-2 rssh -- LTS regression update

Date Reported:
19 Feb 2019
Affected Packages:
rssh
Vulnerable:
Yes
Security database references:
No other external database security references currently available.
More information:

It was discovered that the fix for the security vulnerability released for rssh in 2.3.4-4+deb8u2 via DLA-1660-1 introduced a regression that blocked scp(1) of multiple files from a server using rssh.

Please see #921655 for more information.

For Debian 8 Jessie, this issue has been addressed in rssh version 2.3.4-4+deb8u3.

We recommend that you upgrade your rssh packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS