Information disclosure in OpenSSH - CVE-2016-10011

 

Information disclosure in OpenSSH - CVE-2016-10011

Published: December 21, 2016 / Updated: January 5, 2017


Vulnerability identifier: #VU2068
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10011
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to an error in authfile.c, which may allow a local authenticated user to obtain host private key material.

Successful exploitation of this vulnerability may allow a local user to gain access to otherwise restricted information.


Affected software

OpenSSH
Juniper Junos Space
SCALANCE X320-1-2LD FE
SCALANCE X202-2P IRT PRO
SCALANCE X202-2P IRT
SCALANCE X202-2 IRT
SCALANCE X201-3P IRT PRO
SCALANCE X201-3P IRT
SCALANCE X200-4P IRT
SCALANCE X320-1 FE
SCALANCE X204 IRT
SCALANCE X408-2
SCALANCE XF201-3P IRT
SCALANCE XF202-2P IRT
SCALANCE XF204-2BA IRT
SCALANCE XF204 IRT
SCALANCE X307-2 EEC
SCALANCE X306-1LD FE
SCALANCE X304-2FE
SCALANCE X302-7 EEC
SCALANCE X204 IRT PRO
SCALANCE X204-2LD
SCALANCE X204-2FM
SCALANCE X204-2
SCALANCE X204-2LD TS
SCALANCE X204-2TS
SCALANCE X206-1
SCALANCE X206-1LD
SCALANCE X208
SCALANCE X208PRO
SCALANCE X212-2
SCALANCE X212-2LD
SCALANCE X216
SCALANCE X224
SCALANCE XF204
SCALANCE XF204-2
SCALANCE XF206-1
SCALANCE XF208
Arch Linux
Amazon Linux AMI
SUSE Linux Enterprise Micro
Junos OS
Slackware Linux
Ubuntu
Fedora
SCALANCE XR324-4M EEC
SCALANCE XR324-4M POE
SCALANCE XR324-4M POE TS
SCALANCE X308-2
SCALANCE X310FE
SCALANCE X310
SCALANCE X308-2M TS
SCALANCE X308-2M POE
SCALANCE X308-2M
SCALANCE X308-2LH+
SCALANCE X308-2LH
SCALANCE X308-2LD
SCALANCE X307-3LD
SCALANCE X307-3
SCALANCE XR324-12M
SCALANCE XR324-12M TS
openssh (Alpine package)
openssh
cockpit-bridge-debuginfo
cockpit-bridge
cockpit-ws
cockpit-debugsource
cockpit
cockpit-debuginfo
cockpit-ws-debuginfo
cockpit-dashboard
cockpit-system
IBM BladeCenter Advanced Management Module

How to mitigate CVE-2016-10011

Install the latest version of OpenSSH 7.4.

Juniper Junos Space - update to 18.2R1
openssh (Alpine package) - update to 6.8_p1-r9
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
IBM BladeCenter Advanced Management Module - update to BPET68H-3.68H
SCALANCE X204-2LD - update to 5.2.5
SCALANCE X204-2FM - update to 5.2.5
SCALANCE X204-2 - update to 5.2.5
SCALANCE X204-2LD TS - update to 5.2.5
SCALANCE X204-2TS - update to 5.2.5
SCALANCE X206-1 - update to 5.2.5
SCALANCE X206-1LD - update to 5.2.5
SCALANCE X208 - update to 5.2.5
SCALANCE X208PRO - update to 5.2.5
SCALANCE X212-2 - update to 5.2.5
SCALANCE X212-2LD - update to 5.2.5
SCALANCE X216 - update to 5.2.5
SCALANCE X224 - update to 5.2.5
SCALANCE XF204 - update to 5.2.5
SCALANCE XF204-2 - update to 5.2.5
SCALANCE XF206-1 - update to 5.2.5
SCALANCE XF208 - update to 5.2.5
openssh - update to 7.4p1-1.fc25
cockpit-bridge-debuginfo - update to 195.12-150300.10.6.1
cockpit-bridge - update to 195.12-150300.10.6.1
cockpit-ws - update to 195.12-150300.10.6.1
cockpit-debugsource - update to 195.12-150300.10.6.1
cockpit - update to 195.12-150300.10.6.1
cockpit-debuginfo - update to 195.12-150300.10.6.1
cockpit-ws-debuginfo - update to 195.12-150300.10.6.1
cockpit-dashboard - update to 195.12-150300.10.6.1
cockpit-system - update to 195.12-150300.10.6.1

External References

Related Security Bulletins