Buffer overflow in OpenSSH - CVE-2016-10012
Published: December 21, 2016 / Updated: January 5, 2017
Vulnerability identifier: #VU2075
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10012
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on vulnerable system with root privileges.
The vulnerability exists in sshd due to a flaw in boundary checks in the shared memory manager that may be skipped by some optimizing compilers. A local user can trigger memory corruption and execute arbitrary code with root privileges. The issue is related to m_zback and m_zlib data structures.
Successful exploitation of this vulnerability may allow a local user to elevate privileges.
The vulnerability exists in sshd due to a flaw in boundary checks in the shared memory manager that may be skipped by some optimizing compilers. A local user can trigger memory corruption and execute arbitrary code with root privileges. The issue is related to m_zback and m_zlib data structures.
Successful exploitation of this vulnerability may allow a local user to elevate privileges.
Affected software
OpenSSH
Juniper Junos Space
Arch Linux
Amazon Linux AMI
SUSE Linux Enterprise Micro
Junos OS
Slackware Linux
Ubuntu
Fedora
openssh (Ubuntu package)
openssh (Debian package)
openssh (Alpine package)
openssh
cockpit-ws-debuginfo
cockpit-dashboard
cockpit-system
cockpit-debuginfo
cockpit
cockpit-debugsource
cockpit-ws
cockpit-bridge
cockpit-bridge-debuginfo
Dynamic System Analysis (DSA) Preboot
Integrated Management Module II (IMM2) for BladeCenter Systems
EMC Atmos
Flex System Integrated Management Module (IMM2)
System x Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
Juniper Junos Space
Arch Linux
Amazon Linux AMI
SUSE Linux Enterprise Micro
Junos OS
Slackware Linux
Ubuntu
Fedora
openssh (Ubuntu package)
openssh (Debian package)
openssh (Alpine package)
openssh
cockpit-ws-debuginfo
cockpit-dashboard
cockpit-system
cockpit-debuginfo
cockpit
cockpit-debugsource
cockpit-ws
cockpit-bridge
cockpit-bridge-debuginfo
Dynamic System Analysis (DSA) Preboot
Integrated Management Module II (IMM2) for BladeCenter Systems
EMC Atmos
Flex System Integrated Management Module (IMM2)
System x Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2016-10012
Install the latest version of OpenSSH 7.4.
Juniper Junos Space - update to 18.2R1
openssh (Debian package) - update to 1:6.7p1-5+deb8u6
openssh (Alpine package) - update to 6.8_p1-r9
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System Integrated Management Module (IMM2) - update to 1AOO86D-7.00
System x Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO86D-7.00-bc
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
EMC Atmos - addressed in versions 2.4.2 HF504, 2.4.3 HF504
openssh - update to 7.4p1-1.fc25
cockpit-ws-debuginfo - update to 195.12-150300.10.6.1
cockpit-dashboard - update to 195.12-150300.10.6.1
cockpit-system - update to 195.12-150300.10.6.1
cockpit-debuginfo - update to 195.12-150300.10.6.1
cockpit - update to 195.12-150300.10.6.1
cockpit-debugsource - update to 195.12-150300.10.6.1
cockpit-ws - update to 195.12-150300.10.6.1
cockpit-bridge - update to 195.12-150300.10.6.1
cockpit-bridge-debuginfo - update to 195.12-150300.10.6.1
openssh (Debian package) - update to 1:6.7p1-5+deb8u6
openssh (Alpine package) - update to 6.8_p1-r9
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System Integrated Management Module (IMM2) - update to 1AOO86D-7.00
System x Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO86D-7.00-bc
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
EMC Atmos - addressed in versions 2.4.2 HF504, 2.4.3 HF504
openssh - update to 7.4p1-1.fc25
cockpit-ws-debuginfo - update to 195.12-150300.10.6.1
cockpit-dashboard - update to 195.12-150300.10.6.1
cockpit-system - update to 195.12-150300.10.6.1
cockpit-debuginfo - update to 195.12-150300.10.6.1
cockpit - update to 195.12-150300.10.6.1
cockpit-debugsource - update to 195.12-150300.10.6.1
cockpit-ws - update to 195.12-150300.10.6.1
cockpit-bridge - update to 195.12-150300.10.6.1
cockpit-bridge-debuginfo - update to 195.12-150300.10.6.1
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- Multiple vulnerabilities in OpenSSH for Ubuntu Linux
- Arch Linux update for openssh
- Slackware Linux update for openssh
- Amazon Linux AMI update for openssh
- Ubuntu update for OpenSSH
- Multiple vulnerabilities in Juniper Junos Space
- Debian update for openssh
- Juniper Junos OS update for OpenSSH
- Buffer overflow in openssh (Alpine package)
- Multiple vulnerabilities in Dell EMC Atmos
- SUSE update for cockpit
- Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2)
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Fedora 25 update for openssh