Ubuntu security notices
USN-3538-1: OpenSSH vulnerabilities
USN-3538-1: OpenSSH vulnerabilities Ubuntu Security Notice USN-3538-1 22nd January, 2018 openssh vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in OpenSSH. Software description openssh – secure shell (SSH) for secure access to remote machines Details Jann Horn discovered that OpenSSH incorrectly loaded PKCS#11 modules fromuntrusted directories. A remote attacker could possibly use this issue toexecute arbitrary PKCS#11 modules. This issue only affected Ubuntu 14.04LTS and Ubuntu 16.04 LTS. (CVE-2016-10009) Jann Horn discovered that OpenSSH incorrectly handled permissions onUnix-domain sockets when privilege separation is disabled. A local attackercould possibly use this issue to gain privileges. This issue only affectedUbuntu 16.04 LTS. (CVE-2016-10010) Jann Horn discovered that OpenSSH incorrectly handled certain buffer memoryoperations. A local attacker could possibly use this issue to obtainsensitive information. [ more… ]