SCIENTIFIC-LINUX-ERRATA Archives

March 2016

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 21 Mar 2016 21:49:50 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (43 lines)
Synopsis:          Moderate: openssh security update
Advisory ID:       SLSA-2016:0466-1
Issue Date:        2016-03-21
CVE Numbers:       CVE-2015-5600
                   CVE-2016-3115
--

It was discovered that the OpenSSH server did not sanitize data received
in requests to enable X11 forwarding. An authenticated client with
restricted SSH access could possibly use this flaw to bypass intended
restrictions. (CVE-2016-3115)

It was discovered that the OpenSSH sshd daemon did not check the list of
keyboard-interactive authentication methods for duplicates. A remote
attacker could use this flaw to bypass the MaxAuthTries limit, making it
easier to perform password guessing attacks. (CVE-2015-5600)

After installing this update, the OpenSSH server daemon (sshd) will be
restarted automatically.
--

SL6
  x86_64
    openssh-5.3p1-114.el6_7.x86_64.rpm
    openssh-askpass-5.3p1-114.el6_7.x86_64.rpm
    openssh-clients-5.3p1-114.el6_7.x86_64.rpm
    openssh-debuginfo-5.3p1-114.el6_7.x86_64.rpm
    openssh-server-5.3p1-114.el6_7.x86_64.rpm
    openssh-debuginfo-5.3p1-114.el6_7.i686.rpm
    openssh-ldap-5.3p1-114.el6_7.x86_64.rpm
    pam_ssh_agent_auth-0.9.3-114.el6_7.i686.rpm
    pam_ssh_agent_auth-0.9.3-114.el6_7.x86_64.rpm
  i386
    openssh-5.3p1-114.el6_7.i686.rpm
    openssh-askpass-5.3p1-114.el6_7.i686.rpm
    openssh-clients-5.3p1-114.el6_7.i686.rpm
    openssh-debuginfo-5.3p1-114.el6_7.i686.rpm
    openssh-server-5.3p1-114.el6_7.i686.rpm
    openssh-ldap-5.3p1-114.el6_7.i686.rpm
    pam_ssh_agent_auth-0.9.3-114.el6_7.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2