{"affected":[{"ecosystem_specific":{"binaries":[{"openssh":"6.6p1-29.1","openssh-askpass-gnome":"6.6p1-29.1","openssh-helpers":"6.6p1-29.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Desktop%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.6p1-29.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.6p1-29.1","openssh-askpass-gnome":"6.6p1-29.1","openssh-helpers":"6.6p1-29.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Desktop%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.6p1-29.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.6p1-29.1","openssh-askpass-gnome":"6.6p1-29.1","openssh-fips":"6.6p1-29.1","openssh-helpers":"6.6p1-29.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.6p1-29.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.6p1-29.1","openssh-askpass-gnome":"6.6p1-29.1","openssh-fips":"6.6p1-29.1","openssh-helpers":"6.6p1-29.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.6p1-29.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.6p1-29.1","openssh-askpass-gnome":"6.6p1-29.1","openssh-fips":"6.6p1-29.1","openssh-helpers":"6.6p1-29.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.6p1-29.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.6p1-29.1","openssh-askpass-gnome":"6.6p1-29.1","openssh-fips":"6.6p1-29.1","openssh-helpers":"6.6p1-29.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.6p1-29.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nopenssh was updated to fix several security issues.\n\nThese security issues were fixed:\n* CVE-2015-5352: The x11_open_helper function in channels.c in ssh\n  in OpenSSH when ForwardX11Trusted mode is not used, lacked a check of\n  the refusal deadline for X connections, which made it easier for remote\n  attackers to bypass intended access restrictions via a connection outside\n  of the permitted time window (bsc#936695).\n* CVE-2015-5600: The kbdint_next_device function in auth2-chall.c\n  in sshd in OpenSSH did not properly restrict the processing of\n  keyboard-interactive devices within a single connection, which made it\n  easier for remote attackers to conduct brute-force attacks or cause a\n  denial of service (CPU consumption) via a long and duplicative list in\n  the ssh -oKbdInteractiveDevices option, as demonstrated by a modified\n  client that provides a different password for each pam element on this\n  list (bsc#938746).\n* CVE-2015-4000: Removed and disabled weak DH groups to address LOGJAM (bsc#932483).\n* Hardening patch to fix sftp RCE (bsc#903649).\n* CVE-2015-6563: The monitor component in sshd in OpenSSH accepted\n  extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which\n  allowed local users to conduct impersonation attacks by leveraging any SSH\n  login access in conjunction with control of the sshd uid to send a crafted\n  MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c. (bsc#943010)\n* CVE-2015-6564: Use-after-free vulnerability in the\n  mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH might\n  have allowed local users to gain privileges by leveraging control of the\n  sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request. (bsc#943006)\n\nAlso use %restart_on_update in the trigger script.\n","id":"SUSE-SU-2015:1544-1","modified":"2015-09-09T08:52:05Z","published":"2015-09-09T08:52:05Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151544-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/903649"},{"type":"REPORT","url":"https://bugzilla.suse.com/932483"},{"type":"REPORT","url":"https://bugzilla.suse.com/936695"},{"type":"REPORT","url":"https://bugzilla.suse.com/938746"},{"type":"REPORT","url":"https://bugzilla.suse.com/943006"},{"type":"REPORT","url":"https://bugzilla.suse.com/943010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4000"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-6563"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-6564"}],"related":["CVE-2015-4000","CVE-2015-5352","CVE-2015-5600","CVE-2015-6563","CVE-2015-6564"],"summary":"Security update for openssh","upstream":["CVE-2015-4000","CVE-2015-5352","CVE-2015-5600","CVE-2015-6563","CVE-2015-6564"]}