Denial of service in OpenSSH - CVE-2017-15906
Published: November 15, 2017
Vulnerability identifier: #VU9333
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15906
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The weakness exists in the process_open() function due to improper prevention of write operations in read-only mode. A remote attacker can create zero-length files and cause the service to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists in the process_open() function due to improper prevention of write operations in read-only mode. A remote attacker can create zero-length files and cause the service to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
OpenSSH
Juniper Junos Space
Gentoo Linux
Amazon Linux AMI
IBM AIX
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
Slackware Linux
Ubuntu
Fedora
openssh (Alpine package)
openssh (Debian package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-server-sysvinit
Dynamic System Analysis (DSA) Preboot
Integrated Management Module II (IMM2) for BladeCenter Systems
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
Juniper Junos Space
Gentoo Linux
Amazon Linux AMI
IBM AIX
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
Slackware Linux
Ubuntu
Fedora
openssh (Alpine package)
openssh (Debian package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-server-sysvinit
Dynamic System Analysis (DSA) Preboot
Integrated Management Module II (IMM2) for BladeCenter Systems
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2017-15906
Update to version 7.6.
Juniper Junos Space - update to 18.2R1
openssh (Alpine package) - update to 7.2_p2-r5
openssh (Debian package) - addressed in versions 1:6.7p1-5+deb8u7, 1:7.4p1-10+deb9u4, 1:7.6p1-1, 1:7.9p1-4
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
pam_ssh_agent_auth - update to 0.10.3-2.21
System x Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Flex System Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO86D-7.00-bc
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
openssh - addressed in versions 7.4p1-5.fc25, 7.5p1-4.fc26, 7.6p1-2.fc27
openssh - update to 7.4p1-21
openssh-askpass - update to 7.4p1-21
openssh-cavs - update to 7.4p1-21
openssh-clients - update to 7.4p1-21
openssh-keycat - update to 7.4p1-21
openssh-ldap - update to 7.4p1-21
openssh-server - update to 7.4p1-21
openssh-server-sysvinit - update to 7.4p1-21
openssh (Alpine package) - update to 7.2_p2-r5
openssh (Debian package) - addressed in versions 1:6.7p1-5+deb8u7, 1:7.4p1-10+deb9u4, 1:7.6p1-1, 1:7.9p1-4
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
pam_ssh_agent_auth - update to 0.10.3-2.21
System x Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Flex System Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO86D-7.00-bc
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
openssh - addressed in versions 7.4p1-5.fc25, 7.5p1-4.fc26, 7.6p1-2.fc27
openssh - update to 7.4p1-21
openssh-askpass - update to 7.4p1-21
openssh-cavs - update to 7.4p1-21
openssh-clients - update to 7.4p1-21
openssh-keycat - update to 7.4p1-21
openssh-ldap - update to 7.4p1-21
openssh-server - update to 7.4p1-21
openssh-server-sysvinit - update to 7.4p1-21
External References
Related Security Bulletins
- Denial of service in OpenSSH
- Denial of service in IBM AIX
- Gentoo update for OpenSSH
- Ubuntu update for OpenSSH
- Slackware Linux update for openssh
- Red Hat update for openssh
- Amazon Linux AMI update for openssh
- Multiple vulnerabilities in Juniper Junos Space
- Debian update for openssh
- Denial of service in openssh (Alpine package)
- Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2)
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Anolis OS update for openssh
- Fedora 27 update for openssh
- Fedora 26 update for openssh
- Fedora 25 update for openssh