SUSE-SU-2016:0120-1
Dashboard / Vulnerabilities / SUSE-SU-2016:0120-1
SUSE-SU-2016:0120-1
Summary: Security update for openssh
Details: This update for openssh fixes the following issues: - CVE-2016-0777: A malicious or compromised server could cause the OpenSSH client to expose part or all of the client's private key through the roaming feature (bsc#961642) - CVE-2016-0778: A malicious or compromised server could could trigger a buffer overflow in the OpenSSH client through the roaming feature (bsc#961645) This update disables the undocumented feature supported by the OpenSSH client and a commercial SSH server.
References: https://www.suse.com/support/update/announcement/2016/suse-su-20160120-1/, https://bugzilla.suse.com/961642, https://bugzilla.suse.com/961645, https://www.suse.com/security/cve/CVE-2016-0777, https://www.suse.com/security/cve/CVE-2016-0778
Affected packages
Package
Name: openssh
Purl: pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
