diff CHANGES @ 1234:32cdbbe4b67e

merge 2016.72
author Matt Johnston <matt@ucc.asn.au>
date Thu, 10 Mar 2016 20:57:47 +0800
parents e49a204effe3 2c23d72e06b2
children 3b990ddaea4f
line wrap: on
line diff
--- a/CHANGES	Tue Jan 19 00:34:37 2016 +0800
+++ b/CHANGES	Thu Mar 10 20:57:47 2016 +0800
@@ -1,3 +1,8 @@
+2016.72 - 9 March 2016
+
+- Validate X11 forwarding input. Could allow bypass of authorized_keys command= restrictions,
+  found by github.com/tintinweb. Thanks for Damien Miller for a patch.
+
 2015.71 - 3 December 2015
 
 - Fix "bad buf_incrpos" when data is transferred, broke in 2015.69