{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"low"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2014-9278","title":"Title"},{"category":"description","text":"The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2014-9278","url":"https://www.suse.com/security/cve/CVE-2014-9278"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 908424 for CVE-2014-9278","url":"https://bugzilla.suse.com/908424"}],"title":"SUSE CVE CVE-2014-9278","tracking":{"current_release_date":"2025-04-25T11:36:13Z","generator":{"date":"2023-02-15T05:25:08Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2014-9278","initial_release_date":"2023-02-15T05:25:08Z","revision_history":[{"date":"2023-02-15T05:25:08Z","number":"2","summary":"Current version"},{"date":"2024-07-03T06:33:15Z","number":"3","summary":"Current version"},{"date":"2025-03-14T06:33:08Z","number":"4","summary":"Current version"},{"date":"2025-03-16T11:36:45Z","number":"5","summary":"Current version"},{"date":"2025-04-25T11:36:13Z","number":"6","summary":"Current version"}],"status":"interim","version":"6"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SUSE Liberty Linux 7","product":{"name":"SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7","product_identification_helper":{"cpe":"cpe:/o:suse:sll:7"}}},{"category":"product_name","name":"SUSE Linux Enterprise Desktop 11 SP3","product":{"name":"SUSE Linux Enterprise Desktop 11 SP3","product_id":"SUSE Linux Enterprise Desktop 11 SP3","product_identification_helper":{"cpe":"cpe:/o:suse:suse_sled:11:sp3"}}},{"category":"product_name","name":"SUSE Linux Enterprise Desktop 12","product":{"name":"SUSE Linux Enterprise Desktop 12","product_id":"SUSE Linux Enterprise Desktop 12","product_identification_helper":{"cpe":"cpe:/o:suse:sled:12"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 11 SP1 for Teradata","product":{"name":"SUSE Linux Enterprise Server 11 SP1 for Teradata","product_id":"SUSE Linux Enterprise Server 11 SP1 for Teradata","product_identification_helper":{"cpe":"cpe:/o:suse:suse_sles_teradata:11:sp1"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 11 SP3","product":{"name":"SUSE Linux Enterprise Server 11 SP3","product_id":"SUSE Linux Enterprise Server 11 SP3","product_identification_helper":{"cpe":"cpe:/o:suse:suse_sles:11:sp3"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 12","product":{"name":"SUSE Linux Enterprise Server 12","product_id":"SUSE Linux Enterprise Server 12","product_identification_helper":{"cpe":"cpe:/o:suse:sles:12"}}},{"category":"product_version","name":"openssh","product":{"name":"openssh","product_id":"openssh","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh@?upstream=openssh.src.rpm"}}},{"category":"product_version","name":"openssh-6.6.1p1-11.el7","product":{"name":"openssh-6.6.1p1-11.el7","product_id":"openssh-6.6.1p1-11.el7","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:6.6.1p1:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh@6.6.1p1-11.el7?upstream=openssh-6.6.1p1-11.el7.src.rpm"}}},{"category":"product_version","name":"openssh-askpass","product":{"name":"openssh-askpass","product_id":"openssh-askpass","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh-askpass@?upstream=openssh.src.rpm"}}},{"category":"product_version","name":"openssh-askpass-6.6.1p1-11.el7","product":{"name":"openssh-askpass-6.6.1p1-11.el7","product_id":"openssh-askpass-6.6.1p1-11.el7","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:6.6.1p1:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh-askpass@6.6.1p1-11.el7?upstream=openssh-6.6.1p1-11.el7.src.rpm"}}},{"category":"product_version","name":"openssh-clients-6.6.1p1-11.el7","product":{"name":"openssh-clients-6.6.1p1-11.el7","product_id":"openssh-clients-6.6.1p1-11.el7","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:6.6.1p1:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh-clients@6.6.1p1-11.el7?upstream=openssh-6.6.1p1-11.el7.src.rpm"}}},{"category":"product_version","name":"openssh-fips","product":{"name":"openssh-fips","product_id":"openssh-fips","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh-fips@?upstream=openssh.src.rpm"}}},{"category":"product_version","name":"openssh-helpers","product":{"name":"openssh-helpers","product_id":"openssh-helpers","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh-helpers@?upstream=openssh.src.rpm"}}},{"category":"product_version","name":"openssh-keycat-6.6.1p1-11.el7","product":{"name":"openssh-keycat-6.6.1p1-11.el7","product_id":"openssh-keycat-6.6.1p1-11.el7","product_identification_helper":{"purl":"pkg:rpm/suse/openssh-keycat@6.6.1p1-11.el7"}}},{"category":"product_version","name":"openssh-ldap-6.6.1p1-11.el7","product":{"name":"openssh-ldap-6.6.1p1-11.el7","product_id":"openssh-ldap-6.6.1p1-11.el7","product_identification_helper":{"purl":"pkg:rpm/suse/openssh-ldap@6.6.1p1-11.el7"}}},{"category":"product_version","name":"openssh-server-6.6.1p1-11.el7","product":{"name":"openssh-server-6.6.1p1-11.el7","product_id":"openssh-server-6.6.1p1-11.el7","product_identification_helper":{"cpe":"cpe:2.3:a:openbsd:openssh:6.6.1p1:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/openssh-server@6.6.1p1-11.el7?upstream=openssh-6.6.1p1-11.el7.src.rpm"}}},{"category":"product_version","name":"openssh-server-sysvinit-6.6.1p1-11.el7","product":{"name":"openssh-server-sysvinit-6.6.1p1-11.el7","product_id":"openssh-server-sysvinit-6.6.1p1-11.el7","product_identification_helper":{"purl":"pkg:rpm/suse/openssh-server-sysvinit@6.6.1p1-11.el7"}}},{"category":"product_version","name":"pam_ssh_agent_auth-0.9.3-9.11.el7","product":{"name":"pam_ssh_agent_auth-0.9.3-9.11.el7","product_id":"pam_ssh_agent_auth-0.9.3-9.11.el7","product_identification_helper":{"purl":"pkg:rpm/suse/pam_ssh_agent_auth@0.9.3-9.11.el7"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"openssh-6.6.1p1-11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:openssh-6.6.1p1-11.el7"},"product_reference":"openssh-6.6.1p1-11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"openssh-askpass-6.6.1p1-11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:openssh-askpass-6.6.1p1-11.el7"},"product_reference":"openssh-askpass-6.6.1p1-11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"openssh-clients-6.6.1p1-11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:openssh-clients-6.6.1p1-11.el7"},"product_reference":"openssh-clients-6.6.1p1-11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"openssh-keycat-6.6.1p1-11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:openssh-keycat-6.6.1p1-11.el7"},"product_reference":"openssh-keycat-6.6.1p1-11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"openssh-ldap-6.6.1p1-11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:openssh-ldap-6.6.1p1-11.el7"},"product_reference":"openssh-ldap-6.6.1p1-11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"openssh-server-6.6.1p1-11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:openssh-server-6.6.1p1-11.el7"},"product_reference":"openssh-server-6.6.1p1-11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"openssh-server-sysvinit-6.6.1p1-11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:openssh-server-sysvinit-6.6.1p1-11.el7"},"product_reference":"openssh-server-sysvinit-6.6.1p1-11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"pam_ssh_agent_auth-0.9.3-9.11.el7 as component of SUSE Liberty Linux 7","product_id":"SUSE Liberty Linux 7:pam_ssh_agent_auth-0.9.3-9.11.el7"},"product_reference":"pam_ssh_agent_auth-0.9.3-9.11.el7","relates_to_product_reference":"SUSE Liberty Linux 7"},{"category":"default_component_of","full_product_name":{"name":"openssh as component of SUSE Linux Enterprise Desktop 11 SP3","product_id":"SUSE Linux Enterprise Desktop 11 SP3:openssh"},"product_reference":"openssh","relates_to_product_reference":"SUSE Linux Enterprise Desktop 11 SP3"},{"category":"default_component_of","full_product_name":{"name":"openssh-askpass as component of SUSE Linux Enterprise Desktop 11 SP3","product_id":"SUSE Linux Enterprise Desktop 11 SP3:openssh-askpass"},"product_reference":"openssh-askpass","relates_to_product_reference":"SUSE Linux Enterprise Desktop 11 SP3"},{"category":"default_component_of","full_product_name":{"name":"openssh as component of SUSE Linux Enterprise Desktop 12","product_id":"SUSE Linux Enterprise Desktop 12:openssh"},"product_reference":"openssh","relates_to_product_reference":"SUSE Linux Enterprise Desktop 12"},{"category":"default_component_of","full_product_name":{"name":"openssh-helpers as component of SUSE Linux Enterprise Desktop 12","product_id":"SUSE Linux Enterprise Desktop 12:openssh-helpers"},"product_reference":"openssh-helpers","relates_to_product_reference":"SUSE Linux Enterprise Desktop 12"},{"category":"default_component_of","full_product_name":{"name":"openssh as component of SUSE Linux Enterprise Server 11 SP1 for Teradata","product_id":"SUSE Linux Enterprise Server 11 SP1 for Teradata:openssh"},"product_reference":"openssh","relates_to_product_reference":"SUSE Linux Enterprise Server 11 SP1 for Teradata"},{"category":"default_component_of","full_product_name":{"name":"openssh as component of SUSE Linux Enterprise Server 11 SP3","product_id":"SUSE Linux Enterprise Server 11 SP3:openssh"},"product_reference":"openssh","relates_to_product_reference":"SUSE Linux Enterprise Server 11 SP3"},{"category":"default_component_of","full_product_name":{"name":"openssh-askpass as component of SUSE Linux Enterprise Server 11 SP3","product_id":"SUSE Linux Enterprise Server 11 SP3:openssh-askpass"},"product_reference":"openssh-askpass","relates_to_product_reference":"SUSE Linux Enterprise Server 11 SP3"},{"category":"default_component_of","full_product_name":{"name":"openssh as component of SUSE Linux Enterprise Server 12","product_id":"SUSE Linux Enterprise Server 12:openssh"},"product_reference":"openssh","relates_to_product_reference":"SUSE Linux Enterprise Server 12"},{"category":"default_component_of","full_product_name":{"name":"openssh-fips as component of SUSE Linux Enterprise Server 12","product_id":"SUSE Linux Enterprise Server 12:openssh-fips"},"product_reference":"openssh-fips","relates_to_product_reference":"SUSE Linux Enterprise Server 12"},{"category":"default_component_of","full_product_name":{"name":"openssh-helpers as component of SUSE Linux Enterprise Server 12","product_id":"SUSE Linux Enterprise Server 12:openssh-helpers"},"product_reference":"openssh-helpers","relates_to_product_reference":"SUSE Linux Enterprise Server 12"}]},"vulnerabilities":[{"cve":"CVE-2014-9278","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2014-9278"}],"notes":[{"category":"general","text":"The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.","title":"CVE description"}],"product_status":{"known_not_affected":["SUSE Linux Enterprise Desktop 11 SP3:openssh","SUSE Linux Enterprise Desktop 11 SP3:openssh-askpass","SUSE Linux Enterprise Desktop 12:openssh","SUSE Linux Enterprise Desktop 12:openssh-helpers","SUSE Linux Enterprise Server 11 SP1 for Teradata:openssh","SUSE Linux Enterprise Server 11 SP3:openssh","SUSE Linux Enterprise Server 11 SP3:openssh-askpass","SUSE Linux Enterprise Server 12:openssh","SUSE Linux Enterprise Server 12:openssh-fips","SUSE Linux Enterprise Server 12:openssh-helpers"],"recommended":["SUSE Liberty Linux 7:openssh-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-askpass-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-clients-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-keycat-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-ldap-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-server-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-server-sysvinit-6.6.1p1-11.el7","SUSE Liberty Linux 7:pam_ssh_agent_auth-0.9.3-9.11.el7"]},"references":[{"category":"external","summary":"CVE-2014-9278","url":"https://www.suse.com/security/cve/CVE-2014-9278"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 908424 for CVE-2014-9278","url":"https://bugzilla.suse.com/908424"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["SUSE Liberty Linux 7:openssh-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-askpass-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-clients-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-keycat-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-ldap-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-server-6.6.1p1-11.el7","SUSE Liberty Linux 7:openssh-server-sysvinit-6.6.1p1-11.el7","SUSE Liberty Linux 7:pam_ssh_agent_auth-0.9.3-9.11.el7"]}],"threats":[{"category":"impact","date":"2014-12-04T18:42:30Z","details":"low"}],"title":"CVE-2014-9278"}]}