MGASA-2018-0006
Dashboard / Vulnerabilities / MGASA-2018-0006
MGASA-2018-0006
Summary: Updated openssh packages fix security vulnerability
Details: It was found that the boundary checks in the code implementing support for pre-authentication compression could have been optimized out by certain compilers. An attacker able to compromise the privilege-separated process could possibly use this flaw for further attacks against the privileged monitor process (CVE-2016-10012). The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files (CVE-2017-15906).
References: https://advisories.mageia.org/MGASA-2018-0006.html, https://bugs.mageia.org/show_bug.cgi?id=19987, https://bugzilla.redhat.com/show_bug.cgi?id=1406293, https://lists.fedoraproject.org/archives/list/[email protected]/thread/VZIQDU7D6MLXFXZ4R3ZG2FCH6EDR3MBD/
Affected packages
Package
Name: openssh
Purl: pkg:rpm/mageia/openssh?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
