Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Scientific Linux 6: 2016:0466-1 Moderate: openssh Security Update

Scientific Large Esm H500
Moderate: openssh security update
Date: Mon, 21 Mar 2016 21:49:50 -0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: openssh on SL6.x i386/x86_64
MIME-Version: 1.0
Message-ID: <20160321214950.22522.10309@slpackages.fnal.gov>

Synopsis: Moderate: openssh security update
Advisory ID: SLSA-2016:0466-1
Issue Date: 2016-03-21
CVE Numbers: CVE-2015-5600
 CVE-2016-3115
--

It was discovered that the OpenSSH server did not sanitize data received
in requests to enable X11 forwarding. An authenticated client with
restricted SSH access could possibly use this flaw to bypass intended
restrictions. (CVE-2016-3115)

It was discovered that the OpenSSH sshd daemon did not check the list of
keyboard-interactive authentication methods for duplicates. A remote
attacker could use this flaw to bypass the MaxAuthTries limit, making it
easier to perform password guessing attacks. (CVE-2015-5600)

After installing this update, the OpenSSH server daemon (sshd) will be
restarted automatically.
--

SL6
 x86_64
 openssh-5.3p1-114.el6_7.x86_64.rpm
 openssh-askpass-5.3p1-114.el6_7.x86_64.rpm
 openssh-clients-5.3p1-114.el6_7.x86_64.rpm
 openssh-debuginfo-5.3p1-114.el6_7.x86_64.rpm
 openssh-server-5.3p1-114.el6_7.x86_64.rpm
 openssh-debuginfo-5.3p1-114.el6_7.i686.rpm
 openssh-ldap-5.3p1-114.el6_7.x86_64.rpm
 pam_ssh_agent_auth-0.9.3-114.el6_7.i686.rpm
 pam_ssh_agent_auth-0.9.3-114.el6_7.x86_64.rpm
 i386
 openssh-5.3p1-114.el6_7.i686.rpm
 openssh-askpass-5.3p1-114.el6_7.i686.rpm
 openssh-clients-5.3p1-114.el6_7.i686.rpm
 openssh-debuginfo-5.3p1-114.el6_7.i686.rpm
 openssh-server-5.3p1-114.el6_7.i686.rpm
 openssh-ldap-5.3p1-114.el6_7.i686.rpm
 pam_ssh_agent_auth-0.9.3-114.el6_7.i686.rpm

- Scientific Linux Development Team

Related News

Your message here