CVE-2005-3345 is not patched in breezy version of rssh

Bug #53120 reported by Dave Hall
256
Affects Status Importance Assigned to Milestone
rssh (Ubuntu)
Invalid
Undecided
Unassigned
Breezy
Invalid
Low
Unassigned

Bug Description

Hi,

While trying to track down a fix for rssh segfaulting on AMD64 is came across this http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3345

It is patched in debian but not ubuntu - see http://packages.debian.org/changelogs/pool/main/r/rssh/rssh_2.2.3-1.sarge.1/changelog

I checked and it is fixed in dapper. Given this is a security related package I would consider this pretty serious, even though it is in the universe.

Cheers

Dave

CVE References

Revision history for this message
Martin Pitt (pitti) wrote :

If someone prepares and tests an updated package and attaches a debdiff, I will review and upload it.

Changed in rssh:
importance: Untriaged → Low
status: Unconfirmed → Confirmed
Revision history for this message
Kees Cook (kees) wrote :

Rejecting devel task, marking as Breezy task.

Changed in rssh:
importance: Undecided → Low
status: Unconfirmed → Confirmed
importance: Low → Undecided
status: Confirmed → Rejected
Revision history for this message
Marco Rodrigues (gothicx) wrote :

Breezy support is over.. Today it's Breezy End Of Life!

Changed in rssh:
status: Confirmed → Rejected
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.