SCIENTIFIC-LINUX-ERRATA Archives

March 2016

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Condense Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Content-Type:
text/plain; charset="utf-8"
Date:
Mon, 21 Mar 2016 21:49:50 -0000
Reply-To:
Subject:
MIME-Version:
1.0
Message-ID:
Content-Transfer-Encoding:
7bit
Sender:
Security Errata for Scientific Linux <[log in to unmask]>
From:
Pat Riehecky <[log in to unmask]>
Parts/Attachments:
text/plain (43 lines)
Synopsis:          Moderate: openssh security update
Advisory ID:       SLSA-2016:0466-1
Issue Date:        2016-03-21
CVE Numbers:       CVE-2015-5600
                   CVE-2016-3115
--

It was discovered that the OpenSSH server did not sanitize data received
in requests to enable X11 forwarding. An authenticated client with
restricted SSH access could possibly use this flaw to bypass intended
restrictions. (CVE-2016-3115)

It was discovered that the OpenSSH sshd daemon did not check the list of
keyboard-interactive authentication methods for duplicates. A remote
attacker could use this flaw to bypass the MaxAuthTries limit, making it
easier to perform password guessing attacks. (CVE-2015-5600)

After installing this update, the OpenSSH server daemon (sshd) will be
restarted automatically.
--

SL6
  x86_64
    openssh-5.3p1-114.el6_7.x86_64.rpm
    openssh-askpass-5.3p1-114.el6_7.x86_64.rpm
    openssh-clients-5.3p1-114.el6_7.x86_64.rpm
    openssh-debuginfo-5.3p1-114.el6_7.x86_64.rpm
    openssh-server-5.3p1-114.el6_7.x86_64.rpm
    openssh-debuginfo-5.3p1-114.el6_7.i686.rpm
    openssh-ldap-5.3p1-114.el6_7.x86_64.rpm
    pam_ssh_agent_auth-0.9.3-114.el6_7.i686.rpm
    pam_ssh_agent_auth-0.9.3-114.el6_7.x86_64.rpm
  i386
    openssh-5.3p1-114.el6_7.i686.rpm
    openssh-askpass-5.3p1-114.el6_7.i686.rpm
    openssh-clients-5.3p1-114.el6_7.i686.rpm
    openssh-debuginfo-5.3p1-114.el6_7.i686.rpm
    openssh-server-5.3p1-114.el6_7.i686.rpm
    openssh-ldap-5.3p1-114.el6_7.i686.rpm
    pam_ssh_agent_auth-0.9.3-114.el6_7.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2