Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Wed, 5 Apr 2017 15:06:25 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific LinuxFrom: Pat Riehecky Subject: Security ERRATA Moderate: openssh on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: <20170405150625.2526.65926@slpackages.fnal.gov> Synopsis: Moderate: openssh security and bug fix update Advisory ID: SLSA-2017:0641-1 Issue Date: 2017-03-21 CVE Numbers: CVE-2015-8325 -- Security Fix(es): * It was discovered that the OpenSSH sshd daemon fetched PAM environment settings before running the login program. In configurations with UseLogin=yes and the pam_env PAM module configured to read user environment settings, a local user could use this flaw to execute arbitrary code as root. (CVE-2015-8325) -- SL6 x86_64 openssh-5.3p1-122.el6.x86_64.rpm openssh-askpass-5.3p1-122.el6.x86_64.rpm openssh-clients-5.3p1-122.el6.x86_64.rpm openssh-debuginfo-5.3p1-122.el6.x86_64.rpm openssh-server-5.3p1-122.el6.x86_64.rpm openssh-debuginfo-5.3p1-122.el6.i686.rpm openssh-ldap-5.3p1-122.el6.x86_64.rpm pam_ssh_agent_auth-0.9.3-122.el6.i686.rpm pam_ssh_agent_auth-0.9.3-122.el6.x86_64.rpm i386 openssh-5.3p1-122.el6.i686.rpm openssh-askpass-5.3p1-122.el6.i686.rpm openssh-clients-5.3p1-122.el6.i686.rpm openssh-debuginfo-5.3p1-122.el6.i686.rpm openssh-server-5.3p1-122.el6.i686.rpm openssh-ldap-5.3p1-122.el6.i686.rpm pam_ssh_agent_auth-0.9.3-122.el6.i686.rpm - Scientific Linux Development Team