shield
Security update for openssh
SUSE-SLE-SERVER-12-2019-941
This update for openssh fixes the following issues: Security vulnerabilities addressed: - CVE-2019-6109: Fixed an character encoding issue in the progress display of the scp client that could be used to manipulate client output, allowing for spoofing during file transfers (bsc#1121816). - CVE-2019-6111: Properly validate object names received by the scp client to prevent arbitrary file overwrites when interacting with a malicious SSH server (bsc#1121821). Other issues fixed: - Fixed two race conditions in sshd relating to SIGHUP (bsc#1119183). - Returned proper reason for port forwarding failures (bsc#1090671). - Fixed SSHD termination of multichannel sessions with non-root users (bsc#1115550).
-
Release DateApr 12 2019
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server LTSS 12 s390x
-
Packagesopenssh
Secure Shell Client and Server (Remote Login Program)openssh-askpass-gnome6.6p1-54.32.1 lock rpm lock src
A GNOME-Based Passphrase Dialog for OpenSSHopenssh-fips6.6p1-54.32.1 lock rpm lock src
OpenSSH FIPS cryptomodule HMACsopenssh-helpers6.6p1-54.32.1 lock rpm
OpenSSH AuthorizedKeysCommand helpers6.6p1-54.32.1 lock rpm
SUSE Linux Enterprise Server LTSS 12 x86_64
-
Packagesopenssh
Secure Shell Client and Server (Remote Login Program)openssh-askpass-gnome6.6p1-54.32.1 lock rpm lock src
A GNOME-Based Passphrase Dialog for OpenSSHopenssh-fips6.6p1-54.32.1 lock rpm lock src
OpenSSH FIPS cryptomodule HMACsopenssh-helpers6.6p1-54.32.1 lock rpm
OpenSSH AuthorizedKeysCommand helpers6.6p1-54.32.1 lock rpm