Package "x2goclient"

Name: x2goclient


X2Go Client application (Qt5)

Latest version:
Release: eoan (19.10)
Level: updates
Repository: universe
Homepage: http://wiki.x2go.org/


Download "x2goclient"

Other versions of "x2goclient" in Eoan

Repository Area Version
base universe


Version: 2020-02-03 15:07:15 UTC

  x2goclient ( eoan; urgency=medium

  * debian/patches:
    + Add libssh-regression-fix-CVE-2019-14889.patch. In src/sshprocess.cpp:
      strip ~/, ~user{,/}, ${HOME}{,/} and $HOME{,/} from destination paths
      in scp mode. Fixes: #1428. This was already necessary for pascp (PuTTY-
      based Windows solution for Kerberos support), but newer libssh versions
      with the CVE-2019-14889 also interpret paths as literal strings.
      (LP: #1856795).

 -- Mike Gabriel <email address hidden> Wed, 25 Dec 2019 21:11:41 +0100

1856795 [SRU] X2Go Client broken by libssh CVE-2019-14889 fix
CVE-2019-14889 Unsanitized location in scp could lead to unwanted command execution

About   -   Send Feedback to @ubuntu_updates