ELSA-2015-2088

ELSA-2015-2088 - openssh security, bug fix, and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2015-11-23

Description


[6.6.1p1-22]
- Use the correct constant for glob limits (#1160377)

[6.6.1p1-21]
- Extend memory limit for remote glob in sftp acc. to stat limit (#1160377)

[6.6.1p1-20]
- Fix vulnerabilities published with openssh-7.0 (#1265807)
- Privilege separation weakness related to PAM support
- Use-after-free bug related to PAM support

[6.6.1p1-19]
- Increase limit of files for glob match in sftp to 8192 (#1160377)

[6.6.1p1-18]
- Add GSSAPIKexAlgorithms option for server and client application (#1253062)

[6.6.1p1-17]
- Security fixes released with openssh-6.9 (CVE-2015-5352) (#1247864)
- XSECURITY restrictions bypass under certain conditions in ssh(1) (#1238231)
- weakness of agent locking (ssh-add -x) to password guessing (#1238238)

[6.6.1p1-16]
- only query each keyboard-interactive device once (CVE-2015-5600) (#1245971)

[6.6.1p1-15]
- One more typo in manual page documenting TERM variable (#1162683)
- Fix race condition with auditing messages answers (#1240613)

[6.6.1p1-14]
- Fix ldif schema to have correct spacing on newlines (#1184938)
- Add missing values for sshd test mode (#1187597)
- ssh-copy-id: tcsh doesnt work with multiline strings (#1201758)
- Fix memory problems with newkeys and array transfers (#1223218)
- Enhance AllowGroups documentation in man page (#1150007)

[6.6.1p1-13]
- Increase limit of files for glob match in sftp (#1160377)
- Add pam_reauthorize.so to /etc/pam.d/sshd (#1204233)
- Show all config values in sshd test mode (#1187597)
- Document required selinux boolean for working ssh-ldap-helper (#1178116)
- Consistent usage of pam_namespace in sshd (#1125110)
- Fix auditing when using combination of ForcedCommand and PTY (#1199112)
- Add sftp option to force mode of created files (#1197989)
- Ability to specify an arbitrary LDAP filter in ldap.conf for ssh-ldap-helper (#1201753)
- Provide documentation line for systemd service and socket (#1181591)
- Provide LDIF version of LPK schema (#1184938)
- Document TERM environment variable (#1162683)
- Fix ssh-copy-id on non-sh remote shells (#1201758)
- Do not read RSA1 hostkeys for HostBased authentication in FIPS (#1197666)


Related CVEs


CVE-2015-5600
CVE-2015-6563
CVE-2015-6564

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) openssh-6.6.1p1-22.el7.src.rpm76ad9b980a0b2c5cbffb2acc033e2780ELSA-2019-2143
openssh-6.6.1p1-22.el7.x86_64.rpm44b82c05a023583db0cda2e29bcf7e65ELSA-2019-2143
openssh-askpass-6.6.1p1-22.el7.x86_64.rpm6d97ab7ebede7ac6fd07309348f23434ELSA-2019-2143
openssh-clients-6.6.1p1-22.el7.x86_64.rpma22c52ba6aabc5a042c0a5f403387858ELSA-2019-2143
openssh-keycat-6.6.1p1-22.el7.x86_64.rpm8f812885d14f934aa739ca00531b17c0ELSA-2019-2143
openssh-ldap-6.6.1p1-22.el7.x86_64.rpmc915c57270fc3ca9f579aaee6f5b0bdfELSA-2019-2143
openssh-server-6.6.1p1-22.el7.x86_64.rpme1e562a82d4e1aa9766912f142f44a73ELSA-2019-2143
openssh-server-sysvinit-6.6.1p1-22.el7.x86_64.rpmfcdfab096513bb41ac54833a8491b38fELSA-2019-2143
pam_ssh_agent_auth-0.9.3-9.22.el7.i686.rpmde91f28402aa8870e5d28c3c24aa0972ELSA-2019-2143
pam_ssh_agent_auth-0.9.3-9.22.el7.x86_64.rpmf80b209faa45edbc8595aac487578e78ELSA-2019-2143



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete