[Forgot Password]
Login  Register Subscribe

23631

 
 

127000

 
 

102010

 
 

909

 
 

81309

 
 

123

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2016-0741 -- Oracle openssh

ID: oval:org.secpod.oval:def:1501461Date: (C)2016-05-24   (M)2018-02-06
Class: PATCHFamily: unix




OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix: * It was found that the OpenSSH client did not properly enforce the ForwardX11Timeout setting. A malicious or compromised remote X application could possibly use this flaw to establish a trusted connection to the local X server, even if only untrusted X11 forwarding was requested. * A flaw was found in the way OpenSSH handled PAM authentication when using privilege separation. An attacker with valid credentials on the system and able to fully compromise a non-privileged pre-authentication process using a different flaw could use this flaw to authenticate as other users. * A use-after-free flaw was found in OpenSSH. An attacker able to fully compromise a non-privileged pre-authentication process using a different flaw could possibly cause sshd to crash or execute arbitrary code with root privileges. * An access flaw was discovered in OpenSSH; the OpenSSH client did not correctly handle failures to generate authentication cookies for untrusted X11 forwarding. A malicious or compromised remote X application could possibly use this flaw to establish a trusted connection to the local X server, even if only untrusted X11 forwarding was requested. For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.8 Release Notes and Red Hat Enterprise Linux 6.8 Technical Notes linked from the References section.

Platform:
Oracle Linux 6
Product:
openssh
Reference:
ELSA-2016-0741
CVE-2016-3115
CVE-2015-6563
CVE-2015-5352
CVE-2016-1908
CVE-2015-6564
CVE    5
CVE-2016-1908
CVE-2016-3115
CVE-2015-5352
CVE-2015-6564
...
CPE    5
cpe:/a:openbsd:openssh
cpe:/o:apple:mac_os_x:10.11.0
cpe:/a:openbsd:openssh:6.8
cpe:/a:openbsd:openssh:6.9
...

© 2013 SecPod Technologies