summaryrefslogtreecommitdiffhomepage
path: root/CHANGES
diff options
context:
space:
mode:
authorMatt Johnston <matt@ucc.asn.au>2016-03-09 22:54:15 +0800
committerMatt Johnston <matt@ucc.asn.au>2016-03-09 22:54:15 +0800
commit97dff151ae2c6c5a622b0d625c2e4764de62ca84 (patch)
tree5a51f699af96b9f525ff72e48cdd99b8a91dcfd4 /CHANGES
parent18681875e30e1ea251914417829fdbb50534c9ba (diff)
2016.72
Diffstat (limited to 'CHANGES')
-rw-r--r--CHANGES5
1 files changed, 5 insertions, 0 deletions
diff --git a/CHANGES b/CHANGES
index 7b1e2da..d9d6029 100644
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,8 @@
+2016.72 - 9 March 2016
+
+- Validate X11 forwarding input. Could allow bypass of authorized_keys command= restrictions,
+ found by github.com/tintinweb. Thanks for Damien Miller for a patch.
+
2015.71 - 3 December 2015
- Fix "bad buf_incrpos" when data is transferred, broke in 2015.69