Multiple forced commands being executed

Damien Miller djm at mindrot.org
Wed Feb 2 10:33:01 EST 2011


On Tue, 1 Feb 2011, Oliver Beattie wrote:

> On 1 February 2011 13:34, Damien Miller <djm at mindrot.org> wrote:
> >
> > The bug that caused the authorized_keys file to be parsed in this way
> > was fixed in openssh-5.6 (or possibly earlier). You should try the most
> > recent release (5.7)
> 
> Hmm? we are bound to using Debian packages, I guess it was a little
> earlier, as we are using the latest in Squeeze which is 5.5:
> http://packages.debian.org/squeeze/openssh-server
> 
> I'll see what can be done about upgrading.

You might try building the source packages from a more recent Debian
distribution, or you can backport the fix itself:

http://hg.mindrot.org/openssh/raw-rev/d86d6f9b448a

-d




More information about the openssh-unix-dev mailing list