Consuming excessive CPU resources on the target system in OpenSSH - CVE-2016-6515

 

Consuming excessive CPU resources on the target system in OpenSSH - CVE-2016-6515

Published: August 2, 2016 / Updated: October 30, 2024


Vulnerability identifier: #VU252
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6515
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to consume excessive CPU resources on the target system.

The vulnerability exists in the crypt(3) function, which accepts passwords longer that 1024 characters in auth_password() function in the auth_passwd.c . A remote unauthenticated attacker can submit a very long string as a password and consume excessive CPU resources.

Successful exploitation of this vulnerability may result in denial of service.


Affected software

OpenSSH
SCALANCE X408-2
SCALANCE X320-1 FE
SCALANCE X320-1-2LD FE
SCALANCE X200-4P IRT
SCALANCE XF201-3P IRT
SCALANCE XF202-2P IRT
SCALANCE XF204 IRT
SCALANCE XF204-2BA IRT
SCALANCE X201-3P IRT
SCALANCE X201-3P IRT PRO
SCALANCE X202-2 IRT
SCALANCE X202-2P IRT
SCALANCE X202-2P IRT PRO
SCALANCE X204 IRT
SCALANCE X204 IRT PRO
SCALANCE X302-7 EEC
SCALANCE X304-2FE
SCALANCE X306-1LD FE
SCALANCE X307-2 EEC
SCALANCE X204-2
SCALANCE X204-2FM
SCALANCE X204-2LD
SCALANCE X204-2LD TS
SCALANCE X204-2TS
SCALANCE X206-1
SCALANCE X206-1LD
SCALANCE X208
SCALANCE X208PRO
SCALANCE X212-2
SCALANCE X212-2LD
SCALANCE X216
SCALANCE X224
SCALANCE XF204
SCALANCE XF204-2
SCALANCE XF206-1
SCALANCE XF208
SCALANCE X308-2LH
SCALANCE X308-2LH+
SCALANCE X308-2M
SCALANCE X308-2M POE
SCALANCE X308-2M TS
SCALANCE X310FE
SCALANCE XR324-4M EEC
SCALANCE XR324-4M POE
SCALANCE XR324-4M POE TS
SCALANCE X310
SCALANCE X307-3
SCALANCE X307-3LD
SCALANCE X308-2
SCALANCE X308-2LD
SCALANCE XR324-12M TS
FlashSystem 900 9840-AE2 and 9843-AE2
SCALANCE XR324-12M
FlashSystem 840 9840-AE1 & 9843-AE1
IBM Integrated Management Module
Amazon Linux AMI
FreeBSD
Junos OS
Fedora
openssh (Ubuntu package)
openssh (Debian package)
openssh (Alpine package)
openssh
IBM BladeCenter Advanced Management Module
IBM Spectrum Virtualize for Public Cloud
IBM Storwize V7000
IBM Storwize V5000
IBM Spectrum Virtualize Software
IBM Storwize V3700
IBM FlashSystem V9000
IBM Storwize V3500

How to mitigate CVE-2016-6515

Install the latest version of OpenSSH 7.3.

openssh (Ubuntu package) - addressed in versions 1:5.9p1-5ubuntu1.10, 1:6.6p1-2ubuntu2.8, 1:7.2p2-4ubuntu2.1
openssh (Alpine package) - update to 6.7_p1-r6
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
IBM BladeCenter Advanced Management Module - update to BPET68H-3.68H
IBM Integrated Management Module - update to YUOOH4B - 1.53
SCALANCE X204-2 - update to 5.2.5
SCALANCE X204-2FM - update to 5.2.5
SCALANCE X204-2LD - update to 5.2.5
SCALANCE X204-2LD TS - update to 5.2.5
SCALANCE X204-2TS - update to 5.2.5
SCALANCE X206-1 - update to 5.2.5
SCALANCE X206-1LD - update to 5.2.5
SCALANCE X208 - update to 5.2.5
SCALANCE X208PRO - update to 5.2.5
SCALANCE X212-2 - update to 5.2.5
SCALANCE X212-2LD - update to 5.2.5
SCALANCE X216 - update to 5.2.5
SCALANCE X224 - update to 5.2.5
SCALANCE XF204 - update to 5.2.5
SCALANCE XF204-2 - update to 5.2.5
SCALANCE XF206-1 - update to 5.2.5
SCALANCE XF208 - update to 5.2.5
openssh - update to 7.2p2-12.fc24
IBM Spectrum Virtualize for Public Cloud - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V7000 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V5000 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Spectrum Virtualize Software - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V3700 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM FlashSystem V9000 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V3500 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins