shield
Security update for openssh
SUSE-SLE-SAP-12-SP2-2019-1524
This update for openssh fixes the following issues: Security vulnerabilities addressed: - CVE-2019-6109: Fixed an character encoding issue in the progress display of the scp client that could be used to manipulate client output, allowing for spoofing during file transfers (bsc#1121816). - CVE-2019-6111: Properly validate object names received by the scp client to prevent arbitrary file overwrites when interacting with a malicious SSH server (bsc#1121821). Other issues fixed: - Fixed two race conditions in sshd relating to SIGHUP (bsc#1119183). - Returned proper reason for port forwarding failures (bsc#1090671). - Fixed a double free() in the KDF CAVS testing tool (bsc#1065237).
-
Release DateJun 17 2019
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.2 ppc64le
-
Packagesopenssh
Secure Shell Client and Server (Remote Login Program)openssh-askpass-gnome7.2p2-74.42.8 lock rpm lock src
A GNOME-Based Passphrase Dialog for OpenSSHopenssh-fips7.2p2-74.42.10 lock rpm lock src
OpenSSH FIPS cryptomodule HMACsopenssh-helpers7.2p2-74.42.8 lock rpm
OpenSSH AuthorizedKeysCommand helpers7.2p2-74.42.8 lock rpm
SUSE Linux Enterprise Server for SAP Applications 12.2 x86_64
-
Packagesopenssh
Secure Shell Client and Server (Remote Login Program)openssh-askpass-gnome7.2p2-74.42.8 lock rpm lock src
A GNOME-Based Passphrase Dialog for OpenSSHopenssh-fips7.2p2-74.42.10 lock rpm lock src
OpenSSH FIPS cryptomodule HMACsopenssh-helpers7.2p2-74.42.8 lock rpm
OpenSSH AuthorizedKeysCommand helpers7.2p2-74.42.8 lock rpm