Buffer overflow in OpenSSH - CVE-2016-10012

 

Buffer overflow in OpenSSH - CVE-2016-10012

Published: December 21, 2016 / Updated: January 5, 2017


Vulnerability identifier: #VU2075
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10012
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on vulnerable system with root privileges.

The vulnerability exists in sshd due to a flaw in boundary checks in the shared memory manager that may be skipped by some optimizing compilers. A local user can trigger memory corruption and execute arbitrary code with root privileges. The issue is related to m_zback and m_zlib data structures.

Successful exploitation of this vulnerability may allow a local user to elevate privileges.


Affected software

OpenSSH
Juniper Junos Space
Arch Linux
Amazon Linux AMI
SUSE Linux Enterprise Micro
Junos OS
Slackware Linux
Ubuntu
Fedora
openssh (Ubuntu package)
openssh (Debian package)
openssh (Alpine package)
openssh
cockpit-ws-debuginfo
cockpit-dashboard
cockpit-system
cockpit-debuginfo
cockpit
cockpit-debugsource
cockpit-ws
cockpit-bridge
cockpit-bridge-debuginfo
Dynamic System Analysis (DSA) Preboot
Integrated Management Module II (IMM2) for BladeCenter Systems
EMC Atmos
Flex System Integrated Management Module (IMM2)
System x Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)

How to mitigate CVE-2016-10012

Install the latest version of OpenSSH 7.4.

Juniper Junos Space - update to 18.2R1
openssh (Debian package) - update to 1:6.7p1-5+deb8u6
openssh (Alpine package) - update to 6.8_p1-r9
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System Integrated Management Module (IMM2) - update to 1AOO86D-7.00
System x Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO86D-7.00-bc
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
EMC Atmos - addressed in versions 2.4.2 HF504, 2.4.3 HF504
openssh - update to 7.4p1-1.fc25
cockpit-ws-debuginfo - update to 195.12-150300.10.6.1
cockpit-dashboard - update to 195.12-150300.10.6.1
cockpit-system - update to 195.12-150300.10.6.1
cockpit-debuginfo - update to 195.12-150300.10.6.1
cockpit - update to 195.12-150300.10.6.1
cockpit-debugsource - update to 195.12-150300.10.6.1
cockpit-ws - update to 195.12-150300.10.6.1
cockpit-bridge - update to 195.12-150300.10.6.1
cockpit-bridge-debuginfo - update to 195.12-150300.10.6.1

External References

Related Security Bulletins