![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.843425 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu: Security Advisory (USN-3538-1) |
Summary: | The remote host is missing an update for the 'openssh' package(s) announced via the USN-3538-1 advisory. |
Description: | Summary: The remote host is missing an update for the 'openssh' package(s) announced via the USN-3538-1 advisory. Vulnerability Insight: Jann Horn discovered that OpenSSH incorrectly loaded PKCS#11 modules from untrusted directories. A remote attacker could possibly use this issue to execute arbitrary PKCS#11 modules. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10009) Jann Horn discovered that OpenSSH incorrectly handled permissions on Unix-domain sockets when privilege separation is disabled. A local attacker could possibly use this issue to gain privileges. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10010) Jann Horn discovered that OpenSSH incorrectly handled certain buffer memory operations. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10011) Guido Vranken discovered that OpenSSH incorrectly handled certain shared memory manager operations. A local attacker could possibly use issue to gain privileges. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10012) Michal Zalewski discovered that OpenSSH incorrectly prevented write operations in readonly mode. A remote attacker could possibly use this issue to create zero-length files, leading to a denial of service. (CVE-2017-15906) Affected Software/OS: 'openssh' package(s) on Ubuntu 14.04, Ubuntu 16.04, Ubuntu 17.10. Solution: Please install the updated package(s). CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-10009 BugTraq ID: 94968 http://www.securityfocus.com/bid/94968 https://www.exploit-db.com/exploits/40963/ FreeBSD Security Advisory: FreeBSD-SA-17:01 https://security.FreeBSD.org/advisories/FreeBSD-SA-17:01.openssh.asc http://seclists.org/fulldisclosure/2023/Jul/31 http://packetstormsecurity.com/files/140261/OpenSSH-Arbitrary-Library-Loading.html http://packetstormsecurity.com/files/173661/OpenSSH-Forwarded-SSH-Agent-Remote-Code-Execution.html https://bugs.chromium.org/p/project-zero/issues/detail?id=1009 https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html http://www.openwall.com/lists/oss-security/2016/12/19/2 http://www.openwall.com/lists/oss-security/2023/07/19/9 http://www.openwall.com/lists/oss-security/2023/07/20/1 RedHat Security Advisories: RHSA-2017:2029 https://access.redhat.com/errata/RHSA-2017:2029 http://www.securitytracker.com/id/1037490 https://usn.ubuntu.com/3538-1/ Common Vulnerability Exposure (CVE) ID: CVE-2016-10010 BugTraq ID: 94972 http://www.securityfocus.com/bid/94972 https://www.exploit-db.com/exploits/40962/ http://packetstormsecurity.com/files/140262/OpenSSH-Local-Privilege-Escalation.html https://bugs.chromium.org/p/project-zero/issues/detail?id=1010 Common Vulnerability Exposure (CVE) ID: CVE-2016-10011 BugTraq ID: 94977 http://www.securityfocus.com/bid/94977 Common Vulnerability Exposure (CVE) ID: CVE-2016-10012 BugTraq ID: 94975 http://www.securityfocus.com/bid/94975 Common Vulnerability Exposure (CVE) ID: CVE-2017-15906 BugTraq ID: 101552 http://www.securityfocus.com/bid/101552 https://security.gentoo.org/glsa/201801-05 https://www.oracle.com/security-alerts/cpujan2020.html RedHat Security Advisories: RHSA-2018:0980 https://access.redhat.com/errata/RHSA-2018:0980 |
Copyright | Copyright (C) 2018 Greenbone AG |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |