Amazon Linux AMI : openssh (ALAS-2014-369)
Medium Nessus Plugin ID 78312
SynopsisThe remote Amazon Linux AMI host is missing a security update.
Descriptionsshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.
SolutionRun 'yum update openssh' to update your system.