{"affected":[{"ecosystem_specific":{"binaries":[{"openssh":"5.1p1-41.69.1","openssh-askpass":"5.1p1-41.69.1","openssh-askpass-gnome":"5.1p1-41.69.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP2-LTSS","name":"openssh","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"5.1p1-41.69.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openssh":"5.1p1-41.69.1","openssh-askpass":"5.1p1-41.69.1","openssh-askpass-gnome":"5.1p1-41.69.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP2-LTSS","name":"openssh-askpass-gnome","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"5.1p1-41.69.4"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"openssh was updated to fix four security issues.\n\nThese security issues were fixed:\n- CVE-2015-5352: The x11_open_helper function in channels.c in ssh in OpenSSH when ForwardX11Trusted mode is not used, lacked a check of the refusal deadline for X connections, which made it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window (bsc#936695).\n- CVE-2015-5600: The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH did not properly restrict the processing of keyboard-interactive devices within a single connection, which made it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list (bsc#938746).\n- CVE-2015-4000: Removed and disabled weak DH groups (bsc#932483).\n- Hardening patch to fix sftp RCE (bsc#903649).\n\nThese non-security issues were fixed:\n- bsc#914309: sshd inherits oom_adj -17 on SIGHUP causing DoS potential for oom_killer.\n- bsc#673532: limits.conf fsize change in SLES10SP3 causing problems to WebSphere mqm user.\n  ","id":"SUSE-SU-2015:1840-1","modified":"2015-10-19T16:07:14Z","published":"2015-10-19T16:07:14Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151840-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/673532"},{"type":"REPORT","url":"https://bugzilla.suse.com/903649"},{"type":"REPORT","url":"https://bugzilla.suse.com/905118"},{"type":"REPORT","url":"https://bugzilla.suse.com/914309"},{"type":"REPORT","url":"https://bugzilla.suse.com/932483"},{"type":"REPORT","url":"https://bugzilla.suse.com/936695"},{"type":"REPORT","url":"https://bugzilla.suse.com/938746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4000"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5600"}],"related":["CVE-2015-4000","CVE-2015-5352","CVE-2015-5600"],"summary":"Security update for openssh","upstream":["CVE-2015-4000","CVE-2015-5352","CVE-2015-5600"]}