UbuntuUpdates.org

Package "x2goclient"

Name: x2goclient

Description:

X2Go Client application (Qt4)

Latest version: 4.0.5.1-1ubuntu0.16.04.1
Release: xenial (16.04)
Level: updates
Repository: universe
Homepage: http://wiki.x2go.org/

Links


Download "x2goclient"


Other versions of "x2goclient" in Xenial

Repository Area Version
base universe 4.0.5.1-1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 4.0.5.1-1ubuntu0.16.04.1 2020-02-03 15:07:08 UTC

  x2goclient (4.0.5.1-1ubuntu0.16.04.1) xenial; urgency=medium

  * debian/patches:
    + Add libssh-regression-fix-CVE-2019-14889.patch. In src/sshprocess.cpp:
      strip ~/, ~user{,/}, ${HOME}{,/} and $HOME{,/} from destination paths
      in scp mode. Fixes: #1428. This was already necessary for pascp (PuTTY-
      based Windows solution for Kerberos support), but newer libssh versions
      with the CVE-2019-14889 also interpret paths as literal strings.
      (LP: #1856795).

 -- Mike Gabriel <email address hidden> Wed, 25 Dec 2019 21:11:41 +0100

1856795 [SRU] X2Go Client broken by libssh CVE-2019-14889 fix
CVE-2019-14889 Unsanitized location in scp could lead to unwanted command execution



About   -   Send Feedback to @ubuntu_updates