Information disclosure in Oracle Linux and macOS - CVE-2016-0777

 

Information disclosure in Oracle Linux and macOS - CVE-2016-0777

Published: October 3, 2016 / Updated: January 12, 2017


Vulnerability identifier: #VU718
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0777
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose potentially sensitive information on the target system.
The weakness exists due to access control flaw that allows a malicious user to disclose important data.
Successful exploitation of the vulnerability leads to potentially sensitive information disclosure.

Affected software

Oracle Linux
macOS
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
openssh (Debian package)
openssh (Alpine package)
gsi-openssh
openssh
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
XIV Storage System Gen2
XIV Gen3

How to mitigate CVE-2016-0777


openssh (Debian package) - addressed in versions 1:6.0p1-4+deb7u3, 1:6.7p1-5+deb8u1
openssh (Alpine package) - update to 6.6_p1-r7
gsi-openssh - addressed in versions 6.6.1p1-3.el7, 6.9p1-7.fc22, 7.1p2-1.fc23
openssh - addressed in versions 6.9p1-10.fc22, 7.1p2-1.fc23
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.16.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.8.01.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.8.01.00
XIV Storage System Gen2 - addressed in versions 10.2.4.e-5, 10.2.4.e-8
XIV Gen3 - addressed in versions 11.4.2.a, 11.4.2.d, 11.5.2.a, 11.5.2, 11.6.1.a, 11.6.1

External References

Related Security Bulletins