Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Scientific Linux: 2016:2588-2 Moderate OpenSSH Remote Code Execution Fix

Scientific Large Esm H500
Moderate: openssh security, bug fix, and enhancement update
Date: Wed, 14 Dec 2016 18:15:53 -0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Scott Reid 
Subject: Security ERRATA Moderate: openssh on SL7.x x86_64
MIME-Version: 1.0
Message-ID: <20161214181553.3201.33700@slpackages.fnal.gov>

Synopsis: Moderate: openssh security, bug fix, and enhancement update
Advisory ID: SLSA-2016:2588-2
Issue Date: 2016-11-03
CVE Numbers: CVE-2015-8325
--

Security Fix(es):

* It was discovered that the OpenSSH sshd daemon fetched PAM environment
settings before running the login program. In configurations with
UseLogin=yes and the pam_env PAM module configured to read user
environment settings, a local user could use this flaw to execute
arbitrary code as root. (CVE-2015-8325)

Additional Changes:
--

SL7
 x86_64
 openssh-6.6.1p1-31.el7.x86_64.rpm
 openssh-askpass-6.6.1p1-31.el7.x86_64.rpm
 openssh-clients-6.6.1p1-31.el7.x86_64.rpm
 openssh-debuginfo-6.6.1p1-31.el7.x86_64.rpm
 openssh-keycat-6.6.1p1-31.el7.x86_64.rpm
 openssh-server-6.6.1p1-31.el7.x86_64.rpm
 openssh-debuginfo-6.6.1p1-31.el7.i686.rpm
 openssh-ldap-6.6.1p1-31.el7.x86_64.rpm
 openssh-server-sysvinit-6.6.1p1-31.el7.x86_64.rpm
 pam_ssh_agent_auth-0.9.3-9.31.el7.i686.rpm
 pam_ssh_agent_auth-0.9.3-9.31.el7.x86_64.rpm

- Scientific Linux Development Team

Related News

Your message here