Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:2281-1

Опубликовано: 09 сент. 2016
Источник: suse-cvrf

Описание

Security update for openssh

This update for openssh fixes the following issues:

  • CVE-2016-6210: Prevent user enumeration through the timing of password processing (bsc#989363) [-prevent_timing_user_enumeration]
  • Allow lowering the DH groups parameter limit in server as well as when GSSAPI key exchange is used (bsc#948902)
  • CVE-2016-6515: Limiting the accepted password length to prevent possible DoS (bsc#992533)

Bug fixes:

  • avoid complaining about unset DISPLAY variable (bsc#981654)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
openssh-6.6p1-28.1
openssh-askpass-gnome-6.6p1-28.2
openssh-fips-6.6p1-28.1
openssh-helpers-6.6p1-28.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
openssh-6.6p1-28.1
openssh-askpass-gnome-6.6p1-28.2
openssh-fips-6.6p1-28.1
openssh-helpers-6.6p1-28.1

Описание

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:openssh-6.6p1-28.1
SUSE Linux Enterprise Server 11 SP4:openssh-askpass-gnome-6.6p1-28.2
SUSE Linux Enterprise Server 11 SP4:openssh-fips-6.6p1-28.1
SUSE Linux Enterprise Server 11 SP4:openssh-helpers-6.6p1-28.1

Ссылки

Описание

The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:openssh-6.6p1-28.1
SUSE Linux Enterprise Server 11 SP4:openssh-askpass-gnome-6.6p1-28.2
SUSE Linux Enterprise Server 11 SP4:openssh-fips-6.6p1-28.1
SUSE Linux Enterprise Server 11 SP4:openssh-helpers-6.6p1-28.1

Ссылки