Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

SUSE: 2018:2275-1 Moderate: OpenSSH Denial of Service Fix

suse
Calendar Grey August 9, 2018
Scroller Suse
SUSE has released a security update for OpenSSH that addresses various vulnerabilities and enhances overall security measures. The update includes detailed installation guidelines.
An update that solves four vulnerabilities and has three fixes is now available

Summary

This update for openssh fixes the following issues: Security issues fixed: - CVE-2016-10012: Fix pre-auth compression checks that could be optimized away (bsc#1016370). - CVE-2016-10708: Fix remote denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYSmessage (bsc#1076957). - CVE-2017-15906: Fix r/o sftp-server zero byte file creation (bsc#1065000). - CVE-2008-1483: Fix accidental re-introduction of CVE-2008-1483 (bsc#1069509). Bug fixes: - bsc#1017099: Match conditions with uppercase hostnames fail (bsc#1017099) - bsc#1053972: supportedKeyExchanges diffie-hellman-group1-sha1 is duplicated (bsc#1053972) - bsc#1023275: Messages suppressed after upgrade from SLES 11 SP3 to SP4 (bsc#1023275) Patch Instructions:

References

#1016370 #1017099 #1023275 #1053972 #1065000

#1069509 #1076957

Cross- CVE-2008-1483 CVE-2016-10012 CVE-2016-10708

CVE-2017-15906

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2008-1483.html

https://www.suse.com/security/cve/CVE-2016-10012.html

https://www.suse.com/security/cve/CVE-2016-10708.html

https://www.suse.com/security/cve/CVE-2017-15906.html

https://bugzilla.suse.com/1016370

https://bugzilla.suse.com/1017099

https://bugzilla.suse.com/1023275

https://bugzilla.suse.com/1053972

https://bugzilla.suse.com/1065000

https://bugzilla.suse.com/1069509

https://bugzilla.suse.com/1076957

Announcement ID: SUSE-SU-2018:2275-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.