X2Go Bug report logs - #1428
Connection failed. Cannot create remote file

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Alexanderstr Miete <alexstrbonn@gmail.com>

Date: Sat, 14 Dec 2019 19:10:02 UTC

Severity: normal

Tags: pending

Merged with 1429

Found in version 4.1.2.1

Fixed in version 4.1.2.2

Done: X2Go Release Manager X2Go Release Manager <git-admin@x2go.org>

Bug is archived. No further changes may be made.

Full log


đź”— View this message in rfc822 format

X-Loop: owner@bugs.x2go.org
Subject: Bug#1428: [X2Go-Dev] Bug#1428: X2Go issue (in src:x2goclient) has been marked as pending for release
Reply-To: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>, 1428@bugs.x2go.org
Resent-From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
Resent-To: x2go-dev@lists.x2go.org
Resent-CC: X2Go Developers <x2go-dev@lists.x2go.org>
X-Loop: owner@bugs.x2go.org
Resent-Date: Wed, 25 Dec 2019 20:25:01 +0000
Resent-Message-ID: <handler.1428.B1428.157730541128433@bugs.x2go.org>
Resent-Sender: owner@bugs.x2go.org
X-X2Go-PR-Message: followup 1428
X-X2Go-PR-Package: x2goclient
X-X2Go-PR-Keywords: pending
References: <CAFFk0iqEVR2r+Yr0P5bPS_Orjow3r5PnEOTND7O=aM0K_NiHYA@mail.gmail.com> <20191220193249.A9F595DAF7@ymir.das-netzwerkteam.de> <CAFFk0iqEVR2r+Yr0P5bPS_Orjow3r5PnEOTND7O=aM0K_NiHYA@mail.gmail.com>
Received: via spool by 1428-submit@bugs.x2go.org id=B1428.157730541128433
          (code B ref 1428); Wed, 25 Dec 2019 20:25:01 +0000
Received: (at 1428) by bugs.x2go.org; 25 Dec 2019 20:23:31 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-2.0 required=3.0 tests=BAYES_00,DKIM_SIGNED,
	DKIM_VALID,DKIM_VALID_AU,SPF_HELO_NONE,URIBL_BLOCKED
	autolearn=unavailable autolearn_force=no version=3.4.2
Received: from fregna.das-netzwerkteam.de (fregna.das-netzwerkteam.de [148.251.53.130])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 497ED5DA92;
	Wed, 25 Dec 2019 21:22:18 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [IPv6:2a01:4f8:202:1381::105])
	by fregna.das-netzwerkteam.de (Postfix) with ESMTPS id 316C16028B;
	Wed, 25 Dec 2019 20:22:18 +0000 (UTC)
Received: from das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id 17B45C02E1;
	Wed, 25 Dec 2019 21:22:18 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=das-netzwerkteam.de;
	s=dkim; t=1577305338;
	h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
	 to:to:cc:cc:mime-version:mime-version:content-type:content-type:
	 in-reply-to:in-reply-to:references:references;
	bh=6J01qHurYtbj4gbov3BNTVC49mfJ3ZRN69206HRfN9M=;
	b=mgLWKU9rTO6p+JSzh4b8dkulUrk6U2UWGoIEERn0PkmvHDkPUaV0UgSxqRRq1wXCMU1Joi
	LfYBPlwYAS9YIAEAt5v/Pr2LMiEiql8iyAlOnOv2BOAaxZIa6gbUWupjhoAmZFZZ4iesZM
	yxLQ2fx+xo1F/VlEP3uxV7COacbEf7+jWKfwgcbIhBs5mJQIw5U6X6kDiMepIjKQ4jYROz
	sLnnB7VhbDecuPBquXT0zQ6+fgFlRvySTffgUucwfoaVoy9sDWYCMvoYwaFESyl5iSZJKc
	8z+iGROs6ZEkeXcYI0PxG0HUXgO9XNTtxxiBzQZ45RpZ5k6pxSs7HcJ3jEoxOhJ9jbQEG0
	0pvV+elB8OT5u9ZbFioAG1wFxQ9F2uYkS8I4M9iUssxFcntIJ6ZKPA2OeXAVvDhYRsqXVx
	SE66lZOgGTW6303ymPT7NiROJ5AfEtC1dB5dMNy/T30We3UBSCGaV4ayA6LFSMWjs1o6L1
	Mr5jGsKCiCpsMG4AGOlkJHkoYk0MM61hjdN84xiz06QCLGvB840y9BeYGK48nNSTxd73QB
	U17IWDk2/Os5o41QRdVmUGNDuGu4eKN8KfWBuAwCWEWSVbCDh5OZmg3kSpFdIzRPo82jdb
	akDO5kj893g0uVL5560rND01ZGmIpEkODueZrYXhX4boy0QKaRt8g=
Received: from [37.123.126.38] ([37.123.126.38]) by mail.das-netzwerkteam.de
 (Horde Framework) with HTTPS; Wed, 25 Dec 2019 20:22:18 +0000
Date: Wed, 25 Dec 2019 20:22:18 +0000
Message-ID: <20191225202218.Horde.R1o0BKmDXMXZYhl08zP0ZTs@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: Mihai Moldovan <ionic@ionic.de>, 1428@bugs.x2go.org
Cc: 1428-submitter@bugs.x2go.org, 1429@bugs.debian.org
In-Reply-To: <20191220193249.A9F595DAF7@ymir.das-netzwerkteam.de>
User-Agent: Horde Application Framework 5
Accept-Language: de,en
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 37.123.126.38
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101
 Firefox/68.0
Content-Type: multipart/signed; boundary="=_DVjzD2SLp75alQ3GBZwwTcm";
 protocol="application/pgp-signature"; micalg=pgp-sha512
MIME-Version: 1.0
[Message part 1 (text/plain, inline)]
Hi,

On  Fr 20 Dez 2019 20:32:49 CET, Mihai Moldovan wrote:

> tag #1428 pending
> fixed #1428 4.1.2.2
> thanks
>
> Hello,
>
> X2Go issue #1428 (src:x2goclient) reported by you has been
> fixed in X2Go Git. You can see the changelog below, and you can
> check the diff of the fix at:
>
>     http://code.x2go.org/gitweb?p=x2goclient.git;a=commitdiff;h=ce559d1
>
> The issue will most likely be fixed in src:x2goclient (4.1.2.2).
>
> light+love
> X2Go Git Admin (on behalf of the sender of this mail)
>
> ---
> commit ce559d163a943737fe4160f7233925df2eee1f9a
> Author: Mihai Moldovan <ionic@ionic.de>
> Date:   Fri Dec 20 20:27:31 2019 +0100
>
>     src/sshprocess.cpp: strip ~/, ~user{,/}, ${HOME}{,/} and  
> $HOME{,/} from destination paths in scp mode. Fixes: #1428.
>
>     This was already necessary for pascp (PuTTY-based Windows solution for
>     Kerberos support), but newer libssh versions with the CVE-2019-14889
>     also interpret paths as literal strings.
>
> diff --git a/debian/changelog b/debian/changelog
> index 504d6ae..9f84281 100644
> --- a/debian/changelog
> +++ b/debian/changelog
> @@ -135,6 +135,11 @@ x2goclient (4.1.2.2-0x2go1) UNRELEASED; urgency=medium
>        sound weird first, but this behavior is consistent between all
>        applications - tray icons can be clicked via either button and will
>        always trigger a context menu. Let X2Go Client behave the same way.
> +    - src/sshprocess.cpp: strip ~/, ~user{,/}, ${HOME}{,/} and  
> $HOME{,/} from
> +      destination paths in scp mode. Fixes: #1428. This was already  
> necessary
> +      for pascp (PuTTY-based Windows solution for Kerberos  
> support), but newer
> +      libssh versions with the CVE-2019-14889 also interpret paths  
> as literal
> +      strings.
>    * debian/control:
>      + Add build-depend on pkg-config.
>    * x2goclient.spec:

Please note that I am currently working on getting this  
libssh/CVE-2019-14889 robustness patch into Debian [done] and Ubuntu  
[pending].

Mike
-- 

DAS-NETZWERKTEAM
c\o Technik- und Ökologiezentrum Eckernförde
Mike Gabriel, Marienthaler str. 17, 24340 Eckernförde
mobile: +49 (1520) 1976 148
landline: +49 (4351) 850 8940

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

[Message part 2 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Thu Nov 21 18:38:48 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.