-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 13 Jan 2016 22:08:52 +0100 Source: openssh Binary: openssh-client openssh-server openssh-sftp-server ssh ssh-krb5 ssh-askpass-gnome openssh-client-udeb openssh-server-udeb Architecture: source amd64 all Version: 1:6.7p1-5+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Debian OpenSSH Maintainers <debian-ssh@lists.debian.org> Changed-By: Yves-Alexis Perez <corsac@debian.org> Description: openssh-client - secure shell (SSH) client, for secure access to remote machines openssh-client-udeb - secure shell client for the Debian installer (udeb) openssh-server - secure shell (SSH) server, for secure access from remote machines openssh-server-udeb - secure shell server for the Debian installer (udeb) openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot ssh - secure shell client and server (metapackage) ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad ssh-krb5 - secure shell client and server (transitional package) Changes: openssh (1:6.7p1-5+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Disable roaming in openssh client: roaming code is vulnerable to an information leak (CVE-2016-0777) and heap-based buffer overflow (CVE-2016-0778). Checksums-Sha1: 36d2db7a4a3612da024cacaa5d37edbc153de185 2363 openssh_6.7p1-5+deb8u1.dsc 14e5fbed710ade334d65925e080d1aaeb9c85bf6 1351367 openssh_6.7p1.orig.tar.gz f112857cb5bf9e59097f1356e5b61cfbaaf13680 148124 openssh_6.7p1-5+deb8u1.debian.tar.xz 4f85eb8ec2b8e7c8a3aa4cfd6a64feb11ec0f402 691198 openssh-client_6.7p1-5+deb8u1_amd64.deb f52b67e038431992b8199cfc35f12e309a49c11a 330726 openssh-server_6.7p1-5+deb8u1_amd64.deb 55f6f5eec66b0a40009a7fcac32297427ef229d0 37960 openssh-sftp-server_6.7p1-5+deb8u1_amd64.deb 24c3cca21cdbbfd2747d871be061fbb7722edd45 119772 ssh_6.7p1-5+deb8u1_all.deb 3a7fed300d2e18c534519f72533a243aef6e0961 119284 ssh-krb5_6.7p1-5+deb8u1_all.deb d996924364e75d166812842a85f83c34bbee60b8 127374 ssh-askpass-gnome_6.7p1-5+deb8u1_amd64.deb ba91bf31cfa4d688b1558c7559a0be01c1e69ec5 258386 openssh-client-udeb_6.7p1-5+deb8u1_amd64.udeb 6b7e2fac1b2d2ba42c1ada39d2585c3d9cc9be99 285756 openssh-server-udeb_6.7p1-5+deb8u1_amd64.udeb Checksums-Sha256: a1001440094e04b240ea5f00f257c4e8bff40b3bca3b16211a09c82cba758abd 2363 openssh_6.7p1-5+deb8u1.dsc b2f8394eae858dabbdef7dac10b99aec00c95462753e80342e530bbb6f725507 1351367 openssh_6.7p1.orig.tar.gz 001ea590d8a72adb4f4db79b476822e676185490f50e63bed57bbf4fdaeebdc2 148124 openssh_6.7p1-5+deb8u1.debian.tar.xz adc6511142be4b6fdd32ae958b596af055fb658ed2974e550446722a425808e0 691198 openssh-client_6.7p1-5+deb8u1_amd64.deb 5a99b702841696b18e5bd63e5c7284940edebbfbaf6d978c5198f38e33c65886 330726 openssh-server_6.7p1-5+deb8u1_amd64.deb f23f4e6819c39dca934f6d6ed8c9981233d91bd1b365af78d53aa356051c4ace 37960 openssh-sftp-server_6.7p1-5+deb8u1_amd64.deb 7f7c91dd0d1c440c6c6bc4ee0497226b7af6a61bc32f99f9c09c952167265b6a 119772 ssh_6.7p1-5+deb8u1_all.deb 5e5cf24bc52b0ca771cd7d45e4551a0ba0ffdeeda6b7e9b5d8851e76d4a4a4a4 119284 ssh-krb5_6.7p1-5+deb8u1_all.deb 655bc16be8e02b7c6d56c48212ecb4357eef621ebb720fcba49ea81669755404 127374 ssh-askpass-gnome_6.7p1-5+deb8u1_amd64.deb 823cf472db0878337e93d6f3f09dcdb10061300b1393c0703c9bec43c2f1f473 258386 openssh-client-udeb_6.7p1-5+deb8u1_amd64.udeb 181e4c7b09b639339fd006f4135f0b3193c980fbc364ee7f2813f3a5d658502d 285756 openssh-server-udeb_6.7p1-5+deb8u1_amd64.udeb Files: cae58a6380301cd50aeaf634dc69c0ff 2363 net standard openssh_6.7p1-5+deb8u1.dsc 3246aa79317b1d23cae783a3bf8275d6 1351367 net standard openssh_6.7p1.orig.tar.gz b3f8d0b945e5bd2d295891f2f358a6f5 148124 net standard openssh_6.7p1-5+deb8u1.debian.tar.xz 205d3e600c800fb0120aacec17d8f9ea 691198 net standard openssh-client_6.7p1-5+deb8u1_amd64.deb f64850c23bfcb26df06feb242587c4e0 330726 net optional openssh-server_6.7p1-5+deb8u1_amd64.deb 95b7ff7f3460c9df37045ab94e8f04fb 37960 net optional openssh-sftp-server_6.7p1-5+deb8u1_amd64.deb 06b652de7873cc8483cf49c62a10d047 119772 net extra ssh_6.7p1-5+deb8u1_all.deb d2c9c0bea06e5839ed79638657d970d5 119284 oldlibs extra ssh-krb5_6.7p1-5+deb8u1_all.deb a7b63836747b375bec79dc3adfc6abfa 127374 gnome optional ssh-askpass-gnome_6.7p1-5+deb8u1_amd64.deb f62d54099e0a6dc46d6aa25619b0f39e 258386 debian-installer optional openssh-client-udeb_6.7p1-5+deb8u1_amd64.udeb a5ecf5a583b20269ac3254c580299577 285756 debian-installer optional openssh-server-udeb_6.7p1-5+deb8u1_amd64.udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBCgAGBQJWlr+DAAoJEG3bU/KmdcClgqQIALDdefljbM+zcQAc5HlYhDWB ZwKZ4VY5E4GGnn3kBnjdMRameqJ+20CKzeL+0jD8KEC3/tuOWvC3XJxIbLNfmwkB tuM0pq9iParKW9iFb4NHIIfMkKsqwiNEpoixh9WhomPXI6J03wcFIQrr/dks1clh fllAcxeZqZvvybmy5hxfAtEo2KAzh7VTA1EUKnWvhQTV/fuaouT21vxTfwYg/SEc 776Xy7kVNXDsBLy2mTTCHiZHEUV8ajJa1SwjuYhWuKjrDTg3la5LIsMeRyiDYH8L 0fQi25QKqykllIUdtrFY21fUYu1gcPL77VAAwQJuPsdBW9T/lel7kc6/2HciHh0= =zjy3 -----END PGP SIGNATURE-----