Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.843425
Categoría:Ubuntu Local Security Checks
Título:Ubuntu Update for openssh USN-3538-1
Resumen:The remote host is missing an update for the 'openssh'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'openssh'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Jann Horn discovered that OpenSSH
incorrectly loaded PKCS#11 modules from untrusted directories. A remote attacker
could possibly use this issue to execute arbitrary PKCS#11 modules. This issue
only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10009) Jann Horn
discovered that OpenSSH incorrectly handled permissions on Unix-domain sockets
when privilege separation is disabled. A local attacker could possibly use this
issue to gain privileges. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-10010) Jann Horn discovered that OpenSSH incorrectly handled certain
buffer memory operations. A local attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-10011) Guido Vranken discovered that OpenSSH
incorrectly handled certain shared memory manager operations. A local attacker
could possibly use issue to gain privileges. This issue only affected Ubuntu
14.04 LTS and Ubuntu 16.04 LTS. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-10012) Michal Zalewski discovered that OpenSSH
incorrectly prevented write operations in readonly mode. A remote attacker could
possibly use this issue to create zero-length files, leading to a denial of
service. (CVE-2017-15906)

Affected Software/OS:
openssh on Ubuntu 17.10,
Ubuntu 16.04 LTS,
Ubuntu 14.04 LTS

Solution:
Please Install the Updated Packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-10009
Common Vulnerability Exposure (CVE) ID: CVE-2016-10010
Common Vulnerability Exposure (CVE) ID: CVE-2016-10011
Common Vulnerability Exposure (CVE) ID: CVE-2016-10012
Common Vulnerability Exposure (CVE) ID: CVE-2017-15906
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.