Bug 22460

Summary: openssh missing fixes for CVE-2016-10009 and CVE-2016-10011
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: David Walser <luigiwalser>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: marja11
Version: 5   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: openssh-6.6p1-5.10.mga5.src.rpm CVE:
Status comment: Fix checked into SVN

Description David Walser 2018-01-26 05:12:12 CET
Ubuntu has issued an advisory on January 22:
https://usn.ubuntu.com/usn/usn-3538-1/

They backported fixes for CVE-2016-10009 and CVE-2016-10011 to OpenSSH (for Ubuntu 14.04).  We hadn't been able to backport these fixes ourselves before.

These are minor issues and we don't need to issue an update for just these, but we can add Ubuntu's patches in SVN and save them for any future updates (if there are any).
Comment 1 David Walser 2018-01-28 22:15:22 CET
Patches from Ubuntu added in Mageia 5 SVN.
David Walser 2018-02-02 18:11:29 CET

Status comment: (none) => Fix checked into SVN

Comment 2 David Walser 2018-07-19 15:54:41 CEST
SUSE has issued an advisory for CVE-2016-10708 today (July 19):
http://lists.suse.com/pipermail/sle-security-updates/2018-July/004283.html

The SUSE bug has a link to the upstream commit that fixed the issue (in 7.4):
https://bugzilla.suse.com/show_bug.cgi?id=1076957
Comment 3 David Walser 2018-08-02 17:12:34 CEST
openSUSE has issued an advisory for CVE-2016-10708 on July 28:
https://lists.opensuse.org/opensuse-updates/2018-07/msg00086.html
Comment 4 David Walser 2018-08-16 13:05:49 CEST
One more fix to include:
http://openwall.com/lists/oss-security/2018/08/15/5
Comment 5 David Walser 2018-08-19 21:02:14 CEST
(In reply to David Walser from comment #4)
> One more fix to include:
> http://openwall.com/lists/oss-security/2018/08/15/5

This is CVE-2018-15473:
http://openwall.com/lists/oss-security/2018/08/17/8
Comment 6 Marja Van Waes 2018-10-06 12:55:02 CEST
The limited support Mga5 continued to have after its official EOL has ended, so closing this bug as OLD.

Status: NEW => RESOLVED
Resolution: (none) => OLD
CC: (none) => marja11