Re: ssh+svn vs. bash security bug?
From: Philip Martin <philip.martin_at_wandisco.com>
Date: Sat, 27 Sep 2014 00:45:19 +0100
Vincent Lefevre <vincent-svn_at_vinc17.net> writes:
> How can this be possible? Do you mean that OpenSSH starts the command
OpenSSH uses the login shell for the user, from session.c:
/*
So an svn+ssh installation can be secured by ensuring that the command
A patch to add a no-user-shell option to OpenSSH has been suggested:
http://www.openwall.com/lists/oss-security/2014/09/25/41
However if there is no shell then OpenSSH either has to parse the
There is a similar driver in Subversion: a shell is used when invoking
-- Philip Martin | Subversion Committer WANdisco // *Non-Stop Data*Received on 2014-09-27 01:45:49 CEST |
This is an archived mail posted to the Subversion Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.