openssh (SL6)

Synopsis: Moderate: openssh security and bug fix update
Advisory ID: SLSA-2017:0641-1
Issue Date: 2017-03-21
CVE Numbers: CVE-2015-8325

Security Fix(es):

* It was discovered that the OpenSSH sshd daemon fetched PAM environment
settings before running the login program. In configurations with
UseLogin=yes and the pam_env PAM module configured to read user
environment settings, a local user could use this flaw to execute
arbitrary code as root. (CVE-2015-8325)

SL6
x86_64
openssh-5.3p1-122.el6.x86_64.rpm
openssh-askpass-5.3p1-122.el6.x86_64.rpm
openssh-clients-5.3p1-122.el6.x86_64.rpm
openssh-debuginfo-5.3p1-122.el6.x86_64.rpm
openssh-server-5.3p1-122.el6.x86_64.rpm
openssh-debuginfo-5.3p1-122.el6.i686.rpm
openssh-ldap-5.3p1-122.el6.x86_64.rpm
pam_ssh_agent_auth-0.9.3-122.el6.i686.rpm
pam_ssh_agent_auth-0.9.3-122.el6.x86_64.rpm
i386
openssh-5.3p1-122.el6.i686.rpm
openssh-askpass-5.3p1-122.el6.i686.rpm
openssh-clients-5.3p1-122.el6.i686.rpm
openssh-debuginfo-5.3p1-122.el6.i686.rpm
openssh-server-5.3p1-122.el6.i686.rpm
openssh-ldap-5.3p1-122.el6.i686.rpm
pam_ssh_agent_auth-0.9.3-122.el6.i686.rpm

– Scientific Linux Development Team