[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-369 ---- openssh, pam_ssh_agent_auth

ID: oval:org.secpod.oval:def:1600060Date: (C)2016-01-07   (M)2024-02-19
Class: PATCHFamily: unix




sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

Platform:
Amazon Linux AMI
Product:
openssh
pam_ssh_agent_auth
Reference:
ALAS-2014-369
CVE-2014-2532
CVE-2014-2653
CVE    2
CVE-2014-2532
CVE-2014-2653
CPE    9
cpe:/o:amazon:linux
cpe:/a:openbsd:openssh:6.0
cpe:/a:openbsd:openssh:6.2
cpe:/a:openbsd:openssh:6.1
...

© SecPod Technologies