Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Scientific Linux: SLSA-2016:0043-1 Moderate: OpenSSH Issues

Scientific Large Esm H500
Moderate: openssh security update
Date: Thu, 14 Jan 2016 21:32:39 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: openssh on SL7.x x86_64
MIME-Version: 1.0
Message-ID: <20160114213239.12130.68229@slpackages.fnal.gov>

Synopsis: Moderate: openssh security update
Advisory ID: SLSA-2016:0043-1
Issue Date: 2016-01-14
CVE Numbers: CVE-2016-0777
 CVE-2016-0778
--

An information leak flaw was found in the way the OpenSSH client roaming
feature was implemented. A malicious server could potentially use this
flaw to leak portions of memory (possibly including private SSH keys) of a
successfully authenticated OpenSSH client. (CVE-2016-0777)

A buffer overflow flaw was found in the way the OpenSSH client roaming
feature was implemented. A malicious server could potentially use this
flaw to execute arbitrary code on a successfully authenticated OpenSSH
client if that client used certain non-default configuration options.
(CVE-2016-0778)

After installing this update, the OpenSSH server daemon (sshd) will be
restarted automatically.
--

SL7
 x86_64
 openssh-6.6.1p1-23.el7_2.x86_64.rpm
 openssh-askpass-6.6.1p1-23.el7_2.x86_64.rpm
 openssh-clients-6.6.1p1-23.el7_2.x86_64.rpm
 openssh-debuginfo-6.6.1p1-23.el7_2.x86_64.rpm
 openssh-keycat-6.6.1p1-23.el7_2.x86_64.rpm
 openssh-server-6.6.1p1-23.el7_2.x86_64.rpm
 openssh-debuginfo-6.6.1p1-23.el7_2.i686.rpm
 openssh-ldap-6.6.1p1-23.el7_2.x86_64.rpm
 openssh-server-sysvinit-6.6.1p1-23.el7_2.x86_64.rpm
 pam_ssh_agent_auth-0.9.3-9.23.el7_2.i686.rpm
 pam_ssh_agent_auth-0.9.3-9.23.el7_2.x86_64.rpm

- Scientific Linux Development Team

Related News

Your message here