Improper input validation in OpenSSH - CVE-2016-10009

 

Improper input validation in OpenSSH - CVE-2016-10009

Published: December 19, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU2015
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10009
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on vulnerable ssh client.

The vulnerability exists due to incorrect handling of data passed to PKCS#11 module within ssh-agent. A remote attacker with control over sshd service can execute arbitrary code on vulnerable client.

Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on vulnerable client system but requires that client is connected to malicious SSH server.


Affected software

OpenSSH
Juniper Junos Space
IBM Security Verify Access
Arch Linux
Amazon Linux AMI
SUSE Linux Enterprise Micro
Anolis OS
FreeBSD
Junos OS
Slackware Linux
Ubuntu
openEuler
Fedora
openssh (Ubuntu package)
openssh (Alpine package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-server-sysvinit
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-doc
cockpit-system
cockpit-dashboard
cockpit-ws-debuginfo
cockpit-debuginfo
cockpit
cockpit-debugsource
cockpit-ws
cockpit-bridge
cockpit-bridge-debuginfo
Verify Identity Access Digital Credentials
IBM BladeCenter Advanced Management Module
Session Smart Router
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2016-10009

Install the latest version of OpenSSH 7.4.

Juniper Junos Space - update to 18.2R1
openssh (Alpine package) - update to 6.8_p1-r9
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
IBM BladeCenter Advanced Management Module - update to BPET68H-3.68H
pam_ssh_agent_auth - addressed in versions 0.10.3-2.23, 0.10.3-7.18.0.1, 0.10.4-7.9
pam_ssh_agent_auth - update to 0.10.3-9.27
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
openssh - update to 7.4p1-1.fc25
openssh - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-askpass - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-server-sysvinit - update to 7.4p1-23
openssh-cavs - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-clients - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-keycat - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-ldap - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-server - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-doc - update to 9.0p1-9
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
cockpit-system - update to 195.12-150300.10.6.1
cockpit-dashboard - update to 195.12-150300.10.6.1
cockpit-ws-debuginfo - update to 195.12-150300.10.6.1
cockpit-debuginfo - update to 195.12-150300.10.6.1
cockpit - update to 195.12-150300.10.6.1
cockpit-debugsource - update to 195.12-150300.10.6.1
cockpit-ws - update to 195.12-150300.10.6.1
cockpit-bridge - update to 195.12-150300.10.6.1
cockpit-bridge-debuginfo - update to 195.12-150300.10.6.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins