{"affected":[{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 11 SP3","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 11 SP3","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP3","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"6.2p2-0.21.1","openssh-askpass":"6.2p2-0.21.1","openssh-askpass-gnome":"6.2p2-0.21.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP3","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2p2-0.21.3"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"openssh was updated to fix several security issues and bugs.\n\nThese security issues were fixed:\n* CVE-2015-5352: The x11_open_helper function in channels.c in ssh\n  in OpenSSH when ForwardX11Trusted mode is not used, lacked a check of\n  the refusal deadline for X connections, which made it easier for remote\n  attackers to bypass intended access restrictions via a connection outside\n  of the permitted time window (bsc#936695).\n* CVE-2015-5600: The kbdint_next_device function in auth2-chall.c\n  in sshd in OpenSSH did not properly restrict the processing of\n  keyboard-interactive devices within a single connection, which made it\n  easier for remote attackers to conduct brute-force attacks or cause a\n  denial of service (CPU consumption) via a long and duplicative list in\n  the ssh -oKbdInteractiveDevices option, as demonstrated by a modified\n  client that provides a different password for each pam element on this\n  list (bsc#938746).\n* CVE-2015-4000: Removed and disabled weak DH groups to address LOGJAM (bsc#932483).\n* Hardening patch to fix sftp RCE (bsc#903649).\n* CVE-2015-6563: The monitor component in sshd in OpenSSH accepted\n  extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which\n  allowed local users to conduct impersonation attacks by leveraging any SSH\n  login access in conjunction with control of the sshd uid to send a crafted\n  MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c.\n* CVE-2015-6564: Use-after-free vulnerability in the\n  mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH might\n  have allowed local users to gain privileges by leveraging control of the\n  sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.\n\nThese non-security issues were fixed:\n- bsc#914309: sshd inherits oom_adj -17 on SIGHUP causing DoS potential for oom_killer.\n- bsc#673532: limits.conf fsize change in SLES10SP3 causing problems to WebSphere mqm user.\n- bsc#916549: Fixed support for aesXXX-gcm@openssh.com.\n  ","id":"SUSE-SU-2015:1581-1","modified":"2015-09-17T12:53:08Z","published":"2015-09-17T12:53:08Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151581-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/673532"},{"type":"REPORT","url":"https://bugzilla.suse.com/903649"},{"type":"REPORT","url":"https://bugzilla.suse.com/905118"},{"type":"REPORT","url":"https://bugzilla.suse.com/914309"},{"type":"REPORT","url":"https://bugzilla.suse.com/916549"},{"type":"REPORT","url":"https://bugzilla.suse.com/932483"},{"type":"REPORT","url":"https://bugzilla.suse.com/936695"},{"type":"REPORT","url":"https://bugzilla.suse.com/938746"},{"type":"REPORT","url":"https://bugzilla.suse.com/943006"},{"type":"REPORT","url":"https://bugzilla.suse.com/943010"},{"type":"REPORT","url":"https://bugzilla.suse.com/945493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4000"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-6563"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-6564"}],"related":["CVE-2015-4000","CVE-2015-5352","CVE-2015-5600","CVE-2015-6563","CVE-2015-6564"],"summary":"Security update for openssh","upstream":["CVE-2015-4000","CVE-2015-5352","CVE-2015-5600","CVE-2015-6563","CVE-2015-6564"]}