SUSE-SU-2017:3230-1: moderate: Security update for openssh

sle-updates at lists.suse.com sle-updates at lists.suse.com
Thu Dec 7 10:08:55 MST 2017


   SUSE Security Update: Security update for openssh
______________________________________________________________________________

Announcement ID:    SUSE-SU-2017:3230-1
Rating:             moderate
References:         #1006166 #1048367 #1065000 #1068310 #1069509 
                    
Cross-References:   CVE-2008-1483 CVE-2017-15906
Affected Products:
                    SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
                    SUSE Linux Enterprise Server 12-SP3
                    SUSE Linux Enterprise Server 12-SP2
                    SUSE Linux Enterprise Desktop 12-SP3
                    SUSE Linux Enterprise Desktop 12-SP2
                    SUSE Container as a Service Platform ALL
                    OpenStack Cloud Magnum Orchestration 7
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:

   This update for openssh fixes the following issues:

   Security issue fixed:

   - CVE-2017-15906: Stricter checking of operations in read-only mode in
     sftp server (bsc#1065000).

   Bug fixes:

   - FIPS: Startup selfchecks (bsc#1068310).
   - FIPS: Silent complaints about unsupported key exchange methods
     (bsc#1006166).
   - Refine handling of sockets for X11 forwarding to remove reintroduced
     CVE-2008-1483 (bsc#1069509).
   - Test configuration before running daemon to prevent looping resulting in
     service shutdown (bsc#1048367)


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2:

      zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-2009=1

   - SUSE Linux Enterprise Server 12-SP3:

      zypper in -t patch SUSE-SLE-SERVER-12-SP3-2017-2009=1

   - SUSE Linux Enterprise Server 12-SP2:

      zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-2009=1

   - SUSE Linux Enterprise Desktop 12-SP3:

      zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2017-2009=1

   - SUSE Linux Enterprise Desktop 12-SP2:

      zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-2009=1

   - SUSE Container as a Service Platform ALL:

      zypper in -t patch SUSE-CAASP-ALL-2017-2009=1

   - OpenStack Cloud Magnum Orchestration 7:

      zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-2009=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64):

      openssh-7.2p2-74.11.1
      openssh-askpass-gnome-7.2p2-74.11.3
      openssh-askpass-gnome-debuginfo-7.2p2-74.11.3
      openssh-debuginfo-7.2p2-74.11.1
      openssh-debugsource-7.2p2-74.11.1
      openssh-fips-7.2p2-74.11.1
      openssh-helpers-7.2p2-74.11.1
      openssh-helpers-debuginfo-7.2p2-74.11.1

   - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64):

      openssh-7.2p2-74.11.1
      openssh-askpass-gnome-7.2p2-74.11.3
      openssh-askpass-gnome-debuginfo-7.2p2-74.11.3
      openssh-debuginfo-7.2p2-74.11.1
      openssh-debugsource-7.2p2-74.11.1
      openssh-fips-7.2p2-74.11.1
      openssh-helpers-7.2p2-74.11.1
      openssh-helpers-debuginfo-7.2p2-74.11.1

   - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le s390x x86_64):

      openssh-7.2p2-74.11.1
      openssh-askpass-gnome-7.2p2-74.11.3
      openssh-askpass-gnome-debuginfo-7.2p2-74.11.3
      openssh-debuginfo-7.2p2-74.11.1
      openssh-debugsource-7.2p2-74.11.1
      openssh-fips-7.2p2-74.11.1
      openssh-helpers-7.2p2-74.11.1
      openssh-helpers-debuginfo-7.2p2-74.11.1

   - SUSE Linux Enterprise Desktop 12-SP3 (x86_64):

      openssh-7.2p2-74.11.1
      openssh-askpass-gnome-7.2p2-74.11.3
      openssh-askpass-gnome-debuginfo-7.2p2-74.11.3
      openssh-debuginfo-7.2p2-74.11.1
      openssh-debugsource-7.2p2-74.11.1
      openssh-helpers-7.2p2-74.11.1
      openssh-helpers-debuginfo-7.2p2-74.11.1

   - SUSE Linux Enterprise Desktop 12-SP2 (x86_64):

      openssh-7.2p2-74.11.1
      openssh-askpass-gnome-7.2p2-74.11.3
      openssh-askpass-gnome-debuginfo-7.2p2-74.11.3
      openssh-debuginfo-7.2p2-74.11.1
      openssh-debugsource-7.2p2-74.11.1
      openssh-helpers-7.2p2-74.11.1
      openssh-helpers-debuginfo-7.2p2-74.11.1

   - SUSE Container as a Service Platform ALL (x86_64):

      openssh-7.2p2-74.11.1
      openssh-debuginfo-7.2p2-74.11.1
      openssh-debugsource-7.2p2-74.11.1

   - OpenStack Cloud Magnum Orchestration 7 (x86_64):

      openssh-7.2p2-74.11.1
      openssh-debuginfo-7.2p2-74.11.1
      openssh-debugsource-7.2p2-74.11.1


References:

   https://www.suse.com/security/cve/CVE-2008-1483.html
   https://www.suse.com/security/cve/CVE-2017-15906.html
   https://bugzilla.suse.com/1006166
   https://bugzilla.suse.com/1048367
   https://bugzilla.suse.com/1065000
   https://bugzilla.suse.com/1068310
   https://bugzilla.suse.com/1069509



More information about the sle-updates mailing list