critical
Security update for openssh
SUSE-SLE-DESKTOP-12-SP1-2016-85
This update for openssh fixes the following issues: - CVE-2016-0777: A malicious or compromised server could cause the OpenSSH client to expose part or all of the client's private key through the roaming feature (bsc#961642) - CVE-2016-0778: A malicious or compromised server could could trigger a buffer overflow in the OpenSSH client through the roaming feature (bsc#961645) This update disables the undocumented feature supported by the OpenSSH client and a commercial SSH server.
-
Release DateJan 14 2016
-
References
-
Typesecurity
-
Severitycritical
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Linux Enterprise Desktop 12.1 x86_64
-
Packagesopenssh
Secure Shell Client and Server (Remote Login Program)openssh-askpass-gnome6.6p1-33.1 lock rpm lock src
A GNOME-Based Passphrase Dialog for OpenSSHopenssh-helpers6.6p1-33.1 lock rpm lock src
OpenSSH AuthorizedKeysCommand helpers6.6p1-33.1 lock rpm