Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

SUSE: 2019:1524-1 Moderate: openssh Security Update for File Transfer

suse
Calendar Grey June 17, 2019
Dist Suse Esm H88
SUSE Security Update for openvpn addresses multiple vulnerabilities, classified as moderate, improving connection security with important enhancements.
An update that solves two vulnerabilities and has four fixes is now available

Summary

This update for openssh fixes the following issues: Security vulnerabilities addressed: - CVE-2019-6109: Fixed an character encoding issue in the progress display of the scp client that could be used to manipulate client output, allowing for spoofing during file transfers (bsc#1121816). - CVE-2019-6111: Properly validate object names received by the scp client to prevent arbitrary file overwrites when interacting with a malicious SSH server (bsc#1121821). Other issues fixed: - Fixed two race conditions in sshd relating to SIGHUP (bsc#1119183). - Returned proper reason for port forwarding failures (bsc#1090671). - Fixed a double free() in the KDF CAVS testing tool (bsc#1065237). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1065237 #1090671 #1119183 #1121816 #1121821

#1131709

Cross- CVE-2019-6109 CVE-2019-6111

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Linux Enterprise Desktop 12-SP4

SUSE Linux Enterprise Desktop 12-SP3

SUSE Enterprise Storage 4

SUSE CaaS Platform ALL

SUSE CaaS Platform 3.0

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2019-6109.html

https://www.suse.com/security/cve/CVE-2019-6111.html

https://bugzilla.suse.com/1065237

https://bugzilla.suse.com/1090671

https://bugzilla.suse.com/1119183

https:...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1524-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here