Ubuntu Security Notice 3809-1 - Robert Swiecki discovered that OpenSSH incorrectly handled certain messages. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. It was discovered that OpenSSH incorrectly handled certain requests. An attacker could possibly use this issue to access sensitive information. Various other issues were also addressed.
a84cfe92dbfe11614adbc141355e26a2d23aae9a63b987c3e12f8f9574c9b486
==========================================================================
Ubuntu Security Notice USN-3809-1
November 06, 2018
openssh vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in OpenSSH.
Software Description:
- openssh: secure shell (SSH) for secure access to remote machines
Details:
Robert Swiecki discovered that OpenSSH incorrectly handled certain
messages. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04
LTS. (CVE-2016-10708)
It was discovered that OpenSSH incorrectly handled certain requests.
An attacker could possibly use this issue to access sensitive
information. (CVE-2018-15473)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
openssh-server 1:7.6p1-4ubuntu0.1
Ubuntu 16.04 LTS:
openssh-server 1:7.2p2-4ubuntu2.6
Ubuntu 14.04 LTS:
openssh-server 1:6.6p1-2ubuntu2.11
In general, a standard system update will makVe all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3809-1
CVE-2016-10708, CVE-2018-15473
Package Information:
https://launchpad.net/ubuntu/+source/openssh/1:7.6p1-4ubuntu0.1
https://launchpad.net/ubuntu/+source/openssh/1:7.2p2-4ubuntu2.6
https://launchpad.net/ubuntu/+source/openssh/1:6.6p1-2ubuntu2.11