Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE Linux Enterprise 15: 2021:4567-1 Important: OpenSSL Vulnerability Fix

suse
Calendar Grey September 11, 2018
Dist Suse Esm H88
This SUSE Security Patch resolves a range of openssh vulnerabilities with a moderate severity rating and incorporates critical adjustments and enhancements.
An update that solves four vulnerabilities and has 5 fixes is now available

Summary

This update for openssh provides the following fixes: Security issues fixed: - CVE-2017-15906: Stricter checking of operations in read-only mode in sftp server (bsc#1065000). - CVE-2016-10012: Remove pre-auth compression support from the server to prevent possible cryptographic attacks (bsc#1016370). - CVE-2008-1483: Refine handling of sockets for X11 forwarding to remove reintroduced CVE-2008-1483 (bsc#1069509). - CVE-2016-10708: Prevent DoS due to crashes caused by out-of-sequence NEWKEYS message (bsc#1076957). Bug fixes: - bsc#1017099: Enable case-insensitive hostname matching. - bsc#1023275: Add a new switch for printing diagnostic messages in sftp client's batch mode. - bsc#1048367: systemd integration to work around various race conditions. - bsc#1053972: Remove duplicate KEX method.

References

#1016370 #1017099 #1023275 #1048367 #1053972

#1065000 #1069509 #1076957 #1092582

Cross- CVE-2008-1483 CVE-2016-10012 CVE-2016-10708

CVE-2017-15906

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

https://www.suse.com/security/cve/CVE-2008-1483.html

https://www.suse.com/security/cve/CVE-2016-10012.html

https://www.suse.com/security/cve/CVE-2016-10708.html

https://www.suse.com/security/cve/CVE-2017-15906.html

https://bugzilla.suse.com/1016370

https://bugzilla.suse.com/1017099

https://bugzilla.suse.com/1023275

https://bugzilla.suse.com/1048367

https://bugzilla.suse.com/1053972

https://bugzilla.suse.com/1065000

https://bugzilla.suse.com/1069509

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2685-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here