Bug 1065000 (CVE-2017-15906) - VUL-1: CVE-2017-15906: openssh,openssh-askpass-gnome: r/o sftp-server zero byte file creation
Summary: VUL-1: CVE-2017-15906: openssh,openssh-askpass-gnome: r/o sftp-server zero by...
Status: RESOLVED FIXED
: 1090163 (view as bug list)
Alias: CVE-2017-15906
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All All
: P4 - Low : Normal
Target Milestone: ---
Assignee: Hans Petter Jansson
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/194069/
Whiteboard: CVSSv2:NVD:CVE-2017-15906:5.0:(AV:N/A...
Keywords:
Depends on:
Blocks: 1074115 1090163
  Show dependency treegraph
 
Reported: 2017-10-25 08:50 UTC by Marcus Meissner
Modified: 2024-07-03 08:04 UTC (History)
16 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
foo.patch (601 bytes, patch)
2017-10-25 08:51 UTC, Marcus Meissner
Details | Diff
SLE-11-SP3 patch (925 bytes, patch)
2018-10-10 15:27 UTC, Pedro Monreal Gonzalez
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-10-25 08:50:33 UTC
+++ This bug was initially created as a clone of Bug #1064285 +++

https://www.openssh.com/txt/release-7.6


Security
--------

 * sftp-server(8): in read-only mode, sftp-server was incorrectly
   permitting creation of zero-length files. Reported by Michal
   Zalewski.
Comment 1 Marcus Meissner 2017-10-25 08:51:24 UTC
Created attachment 745777 [details]
foo.patch

patch extracted from 7.5p1 -> 7.6p1 diff
Comment 2 Marcus Meissner 2017-10-25 08:51:44 UTC
I have requested a CVE via webform.
Comment 3 Marcus Meissner 2017-10-26 05:36:05 UTC
CVE-2017-15906 was assigned by mitre.
Comment 8 Swamp Workflow Management 2017-12-07 17:09:31 UTC
SUSE-SU-2017:3230-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1006166,1048367,1065000,1068310,1069509
CVE References: CVE-2008-1483,CVE-2017-15906
Sources used:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    openssh-7.2p2-74.11.1, openssh-askpass-gnome-7.2p2-74.11.3
SUSE Linux Enterprise Server 12-SP3 (src):    openssh-7.2p2-74.11.1, openssh-askpass-gnome-7.2p2-74.11.3
SUSE Linux Enterprise Server 12-SP2 (src):    openssh-7.2p2-74.11.1, openssh-askpass-gnome-7.2p2-74.11.3
SUSE Linux Enterprise Desktop 12-SP3 (src):    openssh-7.2p2-74.11.1, openssh-askpass-gnome-7.2p2-74.11.3
SUSE Linux Enterprise Desktop 12-SP2 (src):    openssh-7.2p2-74.11.1, openssh-askpass-gnome-7.2p2-74.11.3
SUSE Container as a Service Platform ALL (src):    openssh-7.2p2-74.11.1
OpenStack Cloud Magnum Orchestration 7 (src):    openssh-7.2p2-74.11.1
Comment 9 Swamp Workflow Management 2017-12-08 11:15:09 UTC
openSUSE-SU-2017:3243-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1006166,1048367,1065000,1068310,1069509
CVE References: CVE-2008-1483,CVE-2017-15906
Sources used:
openSUSE Leap 42.3 (src):    openssh-7.2p2-15.1, openssh-askpass-gnome-7.2p2-15.1
openSUSE Leap 42.2 (src):    openssh-7.2p2-11.6.1, openssh-askpass-gnome-7.2p2-11.6.1
Comment 10 mike zhu 2018-04-19 07:54:06 UTC
Please provide backport for addressing this issue in openssh-openssl1-6.6p1 package.
Comment 11 Karol Babioch 2018-04-19 08:25:50 UTC
*** Bug 1090163 has been marked as a duplicate of this bug. ***
Comment 16 Swamp Workflow Management 2018-08-09 19:10:13 UTC
SUSE-SU-2018:2275-1: An update that solves four vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1016370,1017099,1023275,1053972,1065000,1069509,1076957
CVE References: CVE-2008-1483,CVE-2016-10012,CVE-2016-10708,CVE-2017-15906
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    openssh-6.6p1-36.3.1, openssh-askpass-gnome-6.6p1-36.3.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    openssh-6.6p1-36.3.1, openssh-askpass-gnome-6.6p1-36.3.1
Comment 18 Swamp Workflow Management 2018-09-11 13:09:17 UTC
SUSE-SU-2018:2685-1: An update that solves four vulnerabilities and has 5 fixes is now available.

Category: security (moderate)
Bug References: 1016370,1017099,1023275,1048367,1053972,1065000,1069509,1076957,1092582
CVE References: CVE-2008-1483,CVE-2016-10012,CVE-2016-10708,CVE-2017-15906
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    openssh-6.6p1-54.15.2, openssh-askpass-gnome-6.6p1-54.15.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    openssh-6.6p1-54.15.2, openssh-askpass-gnome-6.6p1-54.15.1
SUSE Linux Enterprise Server 12-LTSS (src):    openssh-6.6p1-54.15.2, openssh-askpass-gnome-6.6p1-54.15.1
Comment 19 Swamp Workflow Management 2018-09-14 19:09:33 UTC
SUSE-SU-2018:2719-1: An update that solves four vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1016370,1017099,1023275,1053972,1065000,1069509,1076957
CVE References: CVE-2008-1483,CVE-2016-10012,CVE-2016-10708,CVE-2017-15906
Sources used:
SUSE Linux Enterprise Server 11-SECURITY (src):    openssh-openssl1-6.6p1-19.3.1
Comment 21 Pedro Monreal Gonzalez 2018-10-10 15:27:31 UTC
Created attachment 785677 [details]
SLE-11-SP3 patch
Comment 22 Pedro Monreal Gonzalez 2018-10-10 15:31:34 UTC
SLE-10-SP3 has been upgraded to 6.6p1, same as in SLE-11-SP4, and already fixed there.

SLE-11-SP1, with version 5.1p1, is not affected.

SLE-11-SP3 will be submitted shortly.

Submissions for the rest of the codestreams already submitted and released.
Comment 24 Vítězslav Čížek 2018-10-24 14:09:56 UTC
All fixed.
Comment 26 Swamp Workflow Management 2018-10-29 11:09:00 UTC
SUSE-SU-2018:3540-1: An update that solves 5 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1016370,1065000,1076957,1105010,1105180,1106163,1106726
CVE References: CVE-2016-10012,CVE-2016-10708,CVE-2017-15906,CVE-2018-15473,CVE-2018-15919
Sources used:
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    openssh-6.2p2-0.41.5.1, openssh-askpass-gnome-6.2p2-0.41.5.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    openssh-6.2p2-0.41.5.1, openssh-askpass-gnome-6.2p2-0.41.5.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    openssh-6.2p2-0.41.5.1, openssh-askpass-gnome-6.2p2-0.41.5.1
Comment 29 Alexandros Toptsoglou 2020-04-28 15:13:58 UTC
Done