[ubuntu/precise-security] openssh 1:5.9p1-5ubuntu1.10 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Aug 15 16:30:21 UTC 2016


openssh (1:5.9p1-5ubuntu1.10) precise-security; urgency=medium

  * SECURITY UPDATE: user enumeration via covert timing channel
    - debian/patches/CVE-2016-6210-1.patch: determine appropriate salt for
      invalid users in auth-passwd.c, openbsd-compat/xcrypt.c.
    - debian/patches/CVE-2016-6210-2.patch: mitigate timing of disallowed
      users PAM logins in auth-pam.c.
    - debian/patches/CVE-2016-6210-3.patch: search users for one with a
      valid salt in openbsd-compat/xcrypt.c.
    - CVE-2016-6210
  * SECURITY UPDATE: denial of service via long passwords
    - debian/patches/CVE-2016-6515.patch: skip passwords longer than 1k in
      length in auth-passwd.c.
    - CVE-2016-6515

Date: 2016-08-11 15:56:30.196869+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Maintainer: Colin Watson <cjwatson at canonical.com>
https://launchpad.net/ubuntu/+source/openssh/1:5.9p1-5ubuntu1.10
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list