Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 2155-1 Moderate: OpenSSH Wildcard Handling Issue

ubuntu
Calendar Grey March 25, 2014
Scroller Ubuntu
In relation to the OpenSSH vulnerability identified in Ubuntu releases, a remote threat actor could circumvent environment limitations through the use of wildcard characters.
OpenSSH incorrectly handled environment restrictions with wildcards.

Summary

OpenSSH incorrectly handled environment restrictions with wildcards.

Software Description:

- openssh: secure shell (SSH) for secure access to remote machines

Details:

Jann Horn discovered that OpenSSH incorrectly handled wildcards in

AcceptEnv lines. A remote attacker could use this issue to possibly bypass

certain intended environment variable restrictions.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  openssh-server                  1:6.2p2-6ubuntu0.2

Ubuntu 12.10:
  openssh-server                  1:6.0p1-3ubuntu1.1

Ubuntu 12.04 LTS:
  openssh-server                  1:5.9p1-5ubuntu1.2

Ubuntu 10.04 LTS:
  openssh-server                  1:5.3p1-3ubuntu7.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2155-1

CVE-2014-2532

March 25, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.