Re: FreeBSD Security Advisory FreeBSD-SA-08:05.openssh

看板FB_security作者時間17年前 (2008/04/17 19:40), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/7 (看更多)
On Thu, 17 Apr 2008, Peter Pentchev wrote: > On Thu, Apr 17, 2008 at 04:07:56PM +1000, Ian Smith wrote: > > On Thu, 17 Apr 2008, FreeBSD Security Advisories wrote: > > > > > IV. Workaround > > > > > > Disable support for IPv6 in the sshd(8) daemon by setting the option > > > "AddressFamily inet" in /etc/ssh/sshd_config. > > > > > > Disable support for X11 forwarding in the sshd(8) daemon by setting > > > the option "X11Forwarding no" in /etc/ssh/sshd_config. > > > > It's not quite clear from this whether both workarounds are required, or > > just either one, until upgrading? > > Either one, depending on what you want - if your users *need* and use > X11 forwarding, then you wouldn't want to use "X11Forwarding no" :) > > Basically: > - if you DO NOT use X11 forwarding, just disable it with "X11Forwarding no" > - if you use X11 forwarding *and* you DO NOT use IPv6, use the > "AddressFamily inet" line > - if you use X11 forwarding *and* you use IPv6, then you must upgrade. Thanks for the confirmation Peter, also Jille and mouss. cheers, Ian _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #181pT600 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #181pT600 (FB_security)