<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
<generator>
<oval:product_name>Oracle Errata System</oval:product_name>
<oval:product_version>Oracle Linux</oval:product_version>
<oval:schema_version>5.11</oval:schema_version>
<oval:timestamp>2024-09-21T18:49:43</oval:timestamp>
</generator>
<definitions>
<definition id="oval:com.oracle.elsa:def:20152088" version="501" class="patch">
<metadata>
<title>
ELSA-2015-2088:  openssh security, bug fix, and enhancement update (MODERATE)
</title>
<affected family="unix">
<platform>Oracle Linux 7</platform>

</affected>
<reference source="elsa" ref_id="ELSA-2015-2088" ref_url="https://linux.oracle.com/errata/ELSA-2015-2088.html"/>
<reference source="CVE" ref_id="CVE-2015-5600" ref_url="https://linux.oracle.com/cve/CVE-2015-5600.html"/>
<reference source="CVE" ref_id="CVE-2015-6563" ref_url="https://linux.oracle.com/cve/CVE-2015-6563.html"/>
<reference source="CVE" ref_id="CVE-2015-6564" ref_url="https://linux.oracle.com/cve/CVE-2015-6564.html"/>

<description>
[6.6.1p1-22]
- Use the correct constant for glob limits (#1160377)

[6.6.1p1-21]
- Extend memory limit for remote glob in sftp acc. to stat limit (#1160377)

[6.6.1p1-20]
- Fix vulnerabilities published with openssh-7.0 (#1265807)
 - Privilege separation weakness related to PAM support
 - Use-after-free bug related to PAM support

[6.6.1p1-19]
- Increase limit of files for glob match in sftp to 8192 (#1160377)

[6.6.1p1-18]
- Add GSSAPIKexAlgorithms option for server and client application (#1253062)

[6.6.1p1-17]
- Security fixes released with openssh-6.9 (CVE-2015-5352) (#1247864)
 - XSECURITY restrictions bypass under certain conditions in ssh(1) (#1238231)
 - weakness of agent locking (ssh-add -x) to password guessing (#1238238)

[6.6.1p1-16]
- only query each keyboard-interactive device once (CVE-2015-5600) (#1245971)

[6.6.1p1-15]
- One more typo in manual page documenting TERM variable (#1162683)
- Fix race condition with auditing messages answers (#1240613)

[6.6.1p1-14]
- Fix ldif schema to have correct spacing on newlines (#1184938)
- Add missing values for sshd test mode (#1187597)
- ssh-copy-id: tcsh doesnt work with multiline strings (#1201758)
- Fix memory problems with newkeys and array transfers (#1223218)
- Enhance AllowGroups documentation in man page (#1150007)

[6.6.1p1-13]
- Increase limit of files for glob match in sftp (#1160377)
- Add pam_reauthorize.so to /etc/pam.d/sshd (#1204233)
- Show all config values in sshd test mode (#1187597)
- Document required selinux boolean for working ssh-ldap-helper (#1178116)
- Consistent usage of pam_namespace in sshd (#1125110)
- Fix auditing when using combination of ForcedCommand and PTY (#1199112)
- Add sftp option to force mode of created files (#1197989)
- Ability to specify an arbitrary LDAP filter in ldap.conf for ssh-ldap-helper (#1201753)
- Provide documentation line for systemd service and socket (#1181591)
- Provide LDIF version of LPK schema (#1184938)
- Document TERM environment variable (#1162683)
- Fix ssh-copy-id on non-sh remote shells (#1201758)
- Do not read RSA1 hostkeys for HostBased authentication in FIPS (#1197666)

</description>
<!--
 ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ 
-->
<advisory>
<severity>MODERATE</severity>
<rights>Copyright 2015 Oracle, Inc.</rights>
<issued date="2015-11-23"/>
<cve cvss2="4.3/AV:N/AC:M/Au:N/C:N/I:P/A:N" href="https://linux.oracle.com/cve/CVE-2015-5600.html" public="20150716">CVE-2015-5600</cve>
<cve cvss2="6.2/AV:L/AC:H/Au:N/C:C/I:C/A:C" href="https://linux.oracle.com/cve/CVE-2015-6563.html" public="20150811">CVE-2015-6563</cve>
<cve cvss2="4/AV:N/AC:H/Au:N/C:P/I:P/A:N" href="https://linux.oracle.com/cve/CVE-2015-6564.html" public="20150811">CVE-2015-6564</cve>

<affected_cpe_list>
<cpe>cpe:/a:oracle:linux:7:2:base</cpe>
<cpe>cpe:/a:oracle:linux:7::optional_archive</cpe>
<cpe>cpe:/a:oracle:linux:7::latest_archive</cpe>
</affected_cpe_list>
</advisory>
</metadata>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088001" comment="Oracle Linux 7 is installed"/>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088002" comment="Oracle Linux arch is x86_64"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088003" comment="openssh is earlier than 0:6.6.1p1-22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088004" comment="openssh is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088005" comment="openssh-askpass is earlier than 0:6.6.1p1-22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088006" comment="openssh-askpass is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088007" comment="openssh-clients is earlier than 0:6.6.1p1-22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088008" comment="openssh-clients is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088009" comment="openssh-keycat is earlier than 0:6.6.1p1-22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088010" comment="openssh-keycat is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088011" comment="openssh-ldap is earlier than 0:6.6.1p1-22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088012" comment="openssh-ldap is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088013" comment="openssh-server is earlier than 0:6.6.1p1-22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088014" comment="openssh-server is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088015" comment="openssh-server-sysvinit is earlier than 0:6.6.1p1-22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088016" comment="openssh-server-sysvinit is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20152088017" comment="pam_ssh_agent_auth is earlier than 0:0.9.3-9.22.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20152088018" comment="pam_ssh_agent_auth is signed with the Oracle Linux 7 key"/>
</criteria>
</criteria>
</criteria>
</criteria>

</definition>
</definitions>
<!--
 ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<tests>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088001"  version="501" comment="Oracle Linux 7 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088001" />
<state state_ref="oval:com.oracle.elsa:ste:20152088002" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088002"  version="501" comment="Oracle Linux arch is x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088001" />
<state state_ref="oval:com.oracle.elsa:ste:20152088003" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088003"  version="501" comment="openssh is earlier than 0:6.6.1p1-22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088002" />
<state state_ref="oval:com.oracle.elsa:ste:20152088004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088004"  version="501" comment="openssh is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088002" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088005"  version="501" comment="openssh-askpass is earlier than 0:6.6.1p1-22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088003" />
<state state_ref="oval:com.oracle.elsa:ste:20152088004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088006"  version="501" comment="openssh-askpass is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088003" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088007"  version="501" comment="openssh-clients is earlier than 0:6.6.1p1-22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088004" />
<state state_ref="oval:com.oracle.elsa:ste:20152088004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088008"  version="501" comment="openssh-clients is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088004" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088009"  version="501" comment="openssh-keycat is earlier than 0:6.6.1p1-22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088005" />
<state state_ref="oval:com.oracle.elsa:ste:20152088004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088010"  version="501" comment="openssh-keycat is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088005" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088011"  version="501" comment="openssh-ldap is earlier than 0:6.6.1p1-22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088006" />
<state state_ref="oval:com.oracle.elsa:ste:20152088004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088012"  version="501" comment="openssh-ldap is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088006" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088013"  version="501" comment="openssh-server is earlier than 0:6.6.1p1-22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088007" />
<state state_ref="oval:com.oracle.elsa:ste:20152088004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088014"  version="501" comment="openssh-server is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088007" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088015"  version="501" comment="openssh-server-sysvinit is earlier than 0:6.6.1p1-22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088008" />
<state state_ref="oval:com.oracle.elsa:ste:20152088004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088016"  version="501" comment="openssh-server-sysvinit is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088008" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088017"  version="501" comment="pam_ssh_agent_auth is earlier than 0:0.9.3-9.22.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088009" />
<state state_ref="oval:com.oracle.elsa:ste:20152088005" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20152088018"  version="501" comment="pam_ssh_agent_auth is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20152088009" />
<state state_ref="oval:com.oracle.elsa:ste:20152088001" />
</rpminfo_test>

</tests>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ 
-->
<objects>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088004" version="501">
<name>openssh-clients</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088001" version="501">
<name>oraclelinux-release</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088007" version="501">
<name>openssh-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088002" version="501">
<name>openssh</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088009" version="501">
<name>pam_ssh_agent_auth</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088003" version="501">
<name>openssh-askpass</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088006" version="501">
<name>openssh-ldap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088008" version="501">
<name>openssh-server-sysvinit</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20152088005" version="501">
<name>openssh-keycat</name>
</rpminfo_object>

</objects>
<states>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20152088001" version="501">
<signature_keyid operation="equals">72f97b74ec551f03</signature_keyid>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20152088002" version="501">
<version operation="pattern match">^7</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20152088003" version="501">
<arch operation="pattern match">x86_64</arch>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20152088004" version="501">
<evr datatype="evr_string" operation="less than">0:6.6.1p1-22.el7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20152088005" version="501">
<evr datatype="evr_string" operation="less than">0:0.9.3-9.22.el7</evr>
</rpminfo_state>

</states>
</oval_definitions>
