Information disclosure in Oracle Linux and macOS - CVE-2016-0777
Published: October 3, 2016 / Updated: January 12, 2017
Vulnerability identifier: #VU718
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0777
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to disclose potentially sensitive information on the target system.
The weakness exists due to access control flaw that allows a malicious user to disclose important data.
Successful exploitation of the vulnerability leads to potentially sensitive information disclosure.
The weakness exists due to access control flaw that allows a malicious user to disclose important data.
Successful exploitation of the vulnerability leads to potentially sensitive information disclosure.
Affected software
Oracle Linux
macOS
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
openssh (Debian package)
openssh (Alpine package)
gsi-openssh
openssh
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
XIV Storage System Gen2
XIV Gen3
macOS
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
openssh (Debian package)
openssh (Alpine package)
gsi-openssh
openssh
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
XIV Storage System Gen2
XIV Gen3
How to mitigate CVE-2016-0777
openssh (Debian package) - addressed in versions 1:6.0p1-4+deb7u3, 1:6.7p1-5+deb8u1
openssh (Alpine package) - update to 6.6_p1-r7
gsi-openssh - addressed in versions 6.6.1p1-3.el7, 6.9p1-7.fc22, 7.1p2-1.fc23
openssh - addressed in versions 6.9p1-10.fc22, 7.1p2-1.fc23
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.16.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.8.01.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.8.01.00
XIV Storage System Gen2 - addressed in versions 10.2.4.e-5, 10.2.4.e-8
XIV Gen3 - addressed in versions 11.4.2.a, 11.4.2.d, 11.5.2.a, 11.5.2, 11.6.1.a, 11.6.1
openssh (Alpine package) - update to 6.6_p1-r7
gsi-openssh - addressed in versions 6.6.1p1-3.el7, 6.9p1-7.fc22, 7.1p2-1.fc23
openssh - addressed in versions 6.9p1-10.fc22, 7.1p2-1.fc23
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.16.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.8.01.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.8.01.00
XIV Storage System Gen2 - addressed in versions 10.2.4.e-5, 10.2.4.e-8
XIV Gen3 - addressed in versions 11.4.2.a, 11.4.2.d, 11.5.2.a, 11.5.2, 11.6.1.a, 11.6.1
External References
Related Security Bulletins
- Ubuntu update for OpenSSH
- Arch Linux update for openssh
- Debian update for openssh
- Gentoo update for OpenSSH
- OpenSUSE Linux update for openssh
- OpenSUSE Linux update for openssh
- SUSE Linux update for openssh
- SUSE Linux update for openssh
- SUSE Linux update for openssh
- SUSE Linux update for openssh-openssl1
- Amazon Linux AMI update for openssh
- Slackware Linux update for openssh
- Red Hat update for openssh
- Information disclosure in openssh (Alpine package)
- Multiple vulnerabilities in IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru Firmware and QLogic Virtual Fabric Extension Module for IBM BladeCenter
- Multiple vulnerabilities in IBM XIV Gen2
- Multiple vulnerabilities in IBM XIV Gen3
- Fedora 23 update for openssh
- Fedora 22 update for openssh
- Fedora 23 update for gsi-openssh
- Fedora 22 update for gsi-openssh
- Fedora EPEL 7 update for gsi-openssh