EulerOS 2.0 SP1 : openssh (EulerOS-SA-2017-1006)
High Nessus Plugin ID 99852
SynopsisThe remote EulerOS host is missing a security update.
DescriptionAccording to the version of the openssh packages installed, the EulerOS installation on the remote host is affected by the following vulnerability :
- The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that 'OpenSSH upstream does not consider this as a security issue.'(CVE-2016-8858)
Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected openssh package.