Security update for openssh

SUSE Security Update: Security update for openssh
Announcement ID: SUSE-SU-2016:1386-1
Rating: moderate
References: #729190 #932483 #945484 #945493 #947458 #948902 #960414 #961368 #962313 #965576 #970632 #975865
Affected Products:
  • SUSE Linux Enterprise Server 12-SP1
  • SUSE Linux Enterprise Server 12
  • SUSE Linux Enterprise Desktop 12-SP1
  • SUSE Linux Enterprise Desktop 12

  • An update that solves three vulnerabilities and has 9 fixes is now available.

    Description:

    This update for OpenSSH fixes three security issues.

    These security issues were fixed:
    - CVE-2016-3115: Sanitise input for xauth(1) (bsc#970632)
    - CVE-2016-1908: Prevent X11 SECURITY circumvention when forwarding X11
    connections (bsc#962313)
    - CVE-2015-8325: Ignore PAM environment when using login (bsc#975865)

    These non-security issues were fixed:
    - Fix help output of sftp (bsc#945493)
    - Restarting openssh with openssh-fips installed was not working correctly
    (bsc#945484)
    - Fix crashes when /proc is not available in the chroot (bsc#947458)
    - Correctly parse GSSAPI KEX algorithms (bsc#961368)
    - More verbose FIPS mode/CC related documentation in README.FIPS
    (bsc#965576, bsc#960414)
    - Fix PRNG re-seeding (bsc#960414, bsc#729190)
    - Disable DH parameters under 2048 bits by default and allow lowering the
    limit back to the RFC 4419 specified minimum through an option
    (bsc#932483, bsc#948902)

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Server 12-SP1:
      zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-818=1
    • SUSE Linux Enterprise Server 12:
      zypper in -t patch SUSE-SLE-SERVER-12-2016-818=1
    • SUSE Linux Enterprise Desktop 12-SP1:
      zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2016-818=1
    • SUSE Linux Enterprise Desktop 12:
      zypper in -t patch SUSE-SLE-DESKTOP-12-2016-818=1

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64):
      • openssh-6.6p1-42.1
      • openssh-askpass-gnome-6.6p1-42.1
      • openssh-askpass-gnome-debuginfo-6.6p1-42.1
      • openssh-debuginfo-6.6p1-42.1
      • openssh-debugsource-6.6p1-42.1
      • openssh-fips-6.6p1-42.1
      • openssh-helpers-6.6p1-42.1
      • openssh-helpers-debuginfo-6.6p1-42.1
    • SUSE Linux Enterprise Server 12 (ppc64le s390x x86_64):
      • openssh-6.6p1-42.1
      • openssh-askpass-gnome-6.6p1-42.1
      • openssh-askpass-gnome-debuginfo-6.6p1-42.1
      • openssh-debuginfo-6.6p1-42.1
      • openssh-debugsource-6.6p1-42.1
      • openssh-fips-6.6p1-42.1
      • openssh-helpers-6.6p1-42.1
      • openssh-helpers-debuginfo-6.6p1-42.1
    • SUSE Linux Enterprise Desktop 12-SP1 (x86_64):
      • openssh-6.6p1-42.1
      • openssh-askpass-gnome-6.6p1-42.1
      • openssh-askpass-gnome-debuginfo-6.6p1-42.1
      • openssh-debuginfo-6.6p1-42.1
      • openssh-debugsource-6.6p1-42.1
      • openssh-helpers-6.6p1-42.1
      • openssh-helpers-debuginfo-6.6p1-42.1
    • SUSE Linux Enterprise Desktop 12 (x86_64):
      • openssh-6.6p1-42.1
      • openssh-askpass-gnome-6.6p1-42.1
      • openssh-askpass-gnome-debuginfo-6.6p1-42.1
      • openssh-debuginfo-6.6p1-42.1
      • openssh-debugsource-6.6p1-42.1
      • openssh-helpers-6.6p1-42.1
      • openssh-helpers-debuginfo-6.6p1-42.1

    References: