gpp_maybe
Security update for openssh
SUSE-SLE-SAP-12-SP1-2019-125
This update for openssh fixes the following issues: Security issue fixed: - CVE-2018-20685: Fixed an issue where scp client allows remote SSH servers to bypass intended access restrictions (bsc#1121571) - CVE-2019-6109: Fixed an issue where the scp client would allow malicious remote SSH servers to manipulate terminal output via the object name, e.g. by inserting ANSI escape sequences (bsc#1121816) - CVE-2019-6110: Fixed an issue where the scp client would allow malicious remote SSH servers to manipulate stderr output, e.g. by inserting ANSI escape sequences (bsc#1121818) - CVE-2019-6111: Fixed an issue where the scp client would allow malicious remote SSH servers to execute directory traversal attacks and overwrite files (bsc#1121821)
-
Release DateApr 29 2019
-
ReferencesBugzilla: 1121571, 1121816, 1121818, 1121821
CVEs: CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.1 x86_64
-
Packagesopenssh
Secure Shell Client and Server (Remote Login Program)openssh-askpass-gnome6.6p1-54.26.1 lock rpm lock src
A GNOME-Based Passphrase Dialog for OpenSSHopenssh-fips6.6p1-54.26.1 lock rpm lock src
OpenSSH FIPS cryptomodule HMACsopenssh-helpers6.6p1-54.26.1 lock rpm
OpenSSH AuthorizedKeysCommand helpers6.6p1-54.26.1 lock rpm