SB2014032601 - Permissions, Privileges, and Access Controls in openssh (Alpine package)
Published: March 26, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-2532)
The vulnerability allows a remote authenticated user to read and manipulate data.
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=504d9cc36b7cce12fe32cd729d4211c5c4fc3303
- https://git.alpinelinux.org/aports/commit/?id=d3dab2ed5b4e4f080518f87513c4b0958e203159
- https://git.alpinelinux.org/aports/commit/?id=e8f74d41f779d7763f3696d4c921bbc884adca02
- https://git.alpinelinux.org/aports/commit/?id=9e8e49a85f569c1985e7e470926f4320f1a84527