Amazon Linux AMI : openssh (ALAS-2015-568)

Medium Nessus Plugin ID 84928

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

It was reported that when forwarding X11 connections with ForwardX11Trusted=no, connections made after ForwardX11Timeout expired could be permitted and no longer subject to XSECURITY restrictions because of an ineffective timeout check in ssh(1) coupled with 'fail open' behavior in the X11 server when clients attempted connections with expired credentials.

Solution

Run 'yum update openssh' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2015-568.html

Plugin Details

Severity: Medium

ID: 84928

File Name: ala_ALAS-2015-568.nasl

Version: 2.3

Type: local

Agent: unix

Published: 2015/07/23

Updated: 2018/04/18

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:openssh, p-cpe:/a:amazon:linux:openssh-clients, p-cpe:/a:amazon:linux:openssh-debuginfo, p-cpe:/a:amazon:linux:openssh-keycat, p-cpe:/a:amazon:linux:openssh-ldap, p-cpe:/a:amazon:linux:openssh-server, p-cpe:/a:amazon:linux:pam_ssh_agent_auth, cpe:/o:amazon:linux

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 2015/07/22

Reference Information

CVE: CVE-2015-5352

ALAS: 2015-568