Improper input validation in OpenSSH - CVE-2016-10009
Published: December 19, 2016 / Updated: September 14, 2018
Vulnerability identifier: #VU2015
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10009
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on vulnerable ssh client.
The vulnerability exists due to incorrect handling of data passed to PKCS#11 module within ssh-agent. A remote attacker with control over sshd service can execute arbitrary code on vulnerable client.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on vulnerable client system but requires that client is connected to malicious SSH server.
The vulnerability exists due to incorrect handling of data passed to PKCS#11 module within ssh-agent. A remote attacker with control over sshd service can execute arbitrary code on vulnerable client.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on vulnerable client system but requires that client is connected to malicious SSH server.
Affected software
OpenSSH
Juniper Junos Space
IBM Security Verify Access
Arch Linux
Amazon Linux AMI
SUSE Linux Enterprise Micro
Anolis OS
FreeBSD
Junos OS
Slackware Linux
Ubuntu
openEuler
Fedora
openssh (Ubuntu package)
openssh (Alpine package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-server-sysvinit
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-doc
cockpit-system
cockpit-dashboard
cockpit-ws-debuginfo
cockpit-debuginfo
cockpit
cockpit-debugsource
cockpit-ws
cockpit-bridge
cockpit-bridge-debuginfo
Verify Identity Access Digital Credentials
IBM BladeCenter Advanced Management Module
Session Smart Router
Juniper Cloud Native Router
Junos cRPD
Juniper Junos Space
IBM Security Verify Access
Arch Linux
Amazon Linux AMI
SUSE Linux Enterprise Micro
Anolis OS
FreeBSD
Junos OS
Slackware Linux
Ubuntu
openEuler
Fedora
openssh (Ubuntu package)
openssh (Alpine package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-server-sysvinit
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-doc
cockpit-system
cockpit-dashboard
cockpit-ws-debuginfo
cockpit-debuginfo
cockpit
cockpit-debugsource
cockpit-ws
cockpit-bridge
cockpit-bridge-debuginfo
Verify Identity Access Digital Credentials
IBM BladeCenter Advanced Management Module
Session Smart Router
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2016-10009
Install the latest version of OpenSSH 7.4.
Juniper Junos Space - update to 18.2R1
openssh (Alpine package) - update to 6.8_p1-r9
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
IBM BladeCenter Advanced Management Module - update to BPET68H-3.68H
pam_ssh_agent_auth - addressed in versions 0.10.3-2.23, 0.10.3-7.18.0.1, 0.10.4-7.9
pam_ssh_agent_auth - update to 0.10.3-9.27
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
openssh - update to 7.4p1-1.fc25
openssh - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-askpass - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-server-sysvinit - update to 7.4p1-23
openssh-cavs - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-clients - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-keycat - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-ldap - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-server - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-doc - update to 9.0p1-9
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
cockpit-system - update to 195.12-150300.10.6.1
cockpit-dashboard - update to 195.12-150300.10.6.1
cockpit-ws-debuginfo - update to 195.12-150300.10.6.1
cockpit-debuginfo - update to 195.12-150300.10.6.1
cockpit - update to 195.12-150300.10.6.1
cockpit-debugsource - update to 195.12-150300.10.6.1
cockpit-ws - update to 195.12-150300.10.6.1
cockpit-bridge - update to 195.12-150300.10.6.1
cockpit-bridge-debuginfo - update to 195.12-150300.10.6.1
openssh (Alpine package) - update to 6.8_p1-r9
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
IBM BladeCenter Advanced Management Module - update to BPET68H-3.68H
pam_ssh_agent_auth - addressed in versions 0.10.3-2.23, 0.10.3-7.18.0.1, 0.10.4-7.9
pam_ssh_agent_auth - update to 0.10.3-9.27
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
openssh - update to 7.4p1-1.fc25
openssh - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-askpass - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-server-sysvinit - update to 7.4p1-23
openssh-cavs - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-clients - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-keycat - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-ldap - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-server - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-doc - update to 9.0p1-9
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
cockpit-system - update to 195.12-150300.10.6.1
cockpit-dashboard - update to 195.12-150300.10.6.1
cockpit-ws-debuginfo - update to 195.12-150300.10.6.1
cockpit-debuginfo - update to 195.12-150300.10.6.1
cockpit - update to 195.12-150300.10.6.1
cockpit-debugsource - update to 195.12-150300.10.6.1
cockpit-ws - update to 195.12-150300.10.6.1
cockpit-bridge - update to 195.12-150300.10.6.1
cockpit-bridge-debuginfo - update to 195.12-150300.10.6.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- FreeBSD update for OpenSSH
- Multiple vulnerabilities in OpenSSH for Ubuntu Linux
- Arch Linux update for openssh
- Slackware Linux update for openssh
- Amazon Linux AMI update for openssh
- Ubuntu update for OpenSSH
- Multiple vulnerabilities in Juniper Junos Space
- Juniper Junos OS update for OpenSSH
- Improper input validation in openssh (Alpine package)
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module (AMM)
- Amazon Linux AMI update for openssh
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- openEuler update for openssh
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- SUSE update for cockpit
- Amazon Linux AMI update for openssh
- Anolis OS update for openssh
- Anolis OS update for openssh
- Anolis OS update for openssh
- Fedora 25 update for openssh
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access
- Juniper Session Smart Router update for third-party components