SB2016122805 - Information disclosure in openssh (Alpine package)
Published: December 28, 2016
Security Bulletin ID
SB2016122805
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2016-10011)
The vulnerability allows a local user to gain access to potentially sensitive information.The vulnerability exists due to an error in authfile.c, which may allow a local authenticated user to obtain host private key material.
Successful exploitation of this vulnerability may allow a local user to gain access to otherwise restricted information.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=2faa284e53851f31d06fbb36a9853d4622b701f4
- https://git.alpinelinux.org/aports/commit/?id=b27b200a592ab680135f012a56359d52d2540b09
- https://git.alpinelinux.org/aports/commit/?id=cd9e926efc77d1b155c76c221d3d06dace296953
- https://git.alpinelinux.org/aports/commit/?id=d9b200e3dd0b2a723993f2e6d625bdd54e96a041
- https://git.alpinelinux.org/aports/commit/?id=0b546b415bde5a529ffbc08dd3dc0fe78ba82c26
- https://git.alpinelinux.org/aports/commit/?id=fa08f3fc9380fa80827e8384c993a3b7a101089b
- https://git.alpinelinux.org/aports/commit/?id=51458f4830c2da47954b397d85858f068261ca21
- https://git.alpinelinux.org/aports/commit/?id=8d9a5fa9e94e08a1d10f3adbebb033333acc3789
- https://git.alpinelinux.org/aports/commit/?id=9c2376cca71f3342159e374d66950adab7632f80