MGASA-2015-0321
Dashboard / Vulnerabilities / MGASA-2015-0321
MGASA-2015-0321
Summary: Updated openssh packages fix security vulnerabilities
Details: Privilege seaparation weakness related to PAM support allowing the attacker to impersonate other users was found in openssh package. Attackers who could successfully compromise the pre-authentication process for remote code execution and who had valid credentials on the host could impersonate other users (rhbz#1252844). Use-after-free bug was found in openssh package. The vulnerability is exploitable by attackers who could compromise the pre-authentication process for remote code execution (rhbz#1252852).
References: https://advisories.mageia.org/MGASA-2015-0321.html, https://bugs.mageia.org/show_bug.cgi?id=16617, http://openwall.com/lists/oss-security/2015/08/11/9, https://lists.fedoraproject.org/pipermail/package-announce/2015-August/164224.html
Affected packages
Package
Name: openssh
Purl: pkg:rpm/mageia/openssh?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
