Debian Patches
Status for cockpit/337-1+deb13u1
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| ws-be-more-explicit-when-handling-hostnames-on-cli.patch | ws: be more explicit when handling hostnames on cli `cockpit-ws` has never protected hostnames from being interpreted as cli options when passing them to the auth commands (`cockpit-session`, `cockpit-ssh`, `cockpit.beiboot`). There have been a couple of relevant changes over the years: - our move to using cockpit-session via unix socket has removed exposure to this problem for `cockpit-session` - our move from `cockpit-ssh` (glib argument parser) to `cockpit.beiboot` (Python argparse) has unfortunately exposed us to https://github.com/python/cpython/issues/66623 which means (due to a strange heuristic) that arguments starting with '-' can be interpreted as positionals if they also have spaces in them This gives a way to get a hostname starting with a `-` to ssh (where it *will* be interpreted as an option) and the following argument (the python invocation on the remote) will be interpreted as the hostname. Fortunately, new versions of ssh will reject this hostname. In any case, we should firm up the code here and add `--` to ensure that it's definitely interpreted as a hostname by ssh. For a similar reason add a `--` to the ssh command in `cockpit-ws`. CVE-2026-4631 |
Allison Karlitskaya <allison.karlitskaya@redhat.com> | no | debian | https://github.com/cockpit-project/cockpit/commit/9d0695647 | 2026-03-24 |
All known versions for source package 'cockpit'
- 366-1 (sid)
- 365-1 (forky)
- 365-1~bpo13+1 (trixie-backports)
- 337-1+deb13u1 (trixie)
- 337-1~bpo12+1 (bookworm-backports)
- 287.1-0+deb12u3 (bookworm)
- 287.1-0+deb12u2 (bookworm-security)
