Bug 8935

Summary: OpenSSH client: CVE-2016-0777, CVE-2016-0778 and CVE-2016-1907
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Armin Kuster <akuster>
Component: coreAssignee: Armin Kuster <akuster>
Status: VERIFIED FIXED QA Contact: Alexandru Roman <alexandru.costinx.roman>
Severity: normal    
Priority: High CC: bogdanx.a.voiculescu, joshuagloe, meta.mr.watcher, meta.watcher
Version: 2.0.1   
Target Milestone: 2.0.2   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Armin Kuster 2016-01-15 18:47:25 UTC
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature 

CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
Comment 1 Armin Kuster 2016-01-15 18:50:26 UTC
Master package was updated to 7.1p2

http://cgit.openembedded.org/openembedded-core/commit/?id=b3b679d5be86f73d1a06c7230cb00872f0a407b5

Jethro is at version 7.1.p1 so cherry-picking this should be ok.

Fido needs patches.. working on them.
Comment 2 Armin Kuster 2016-01-15 18:53:25 UTC
new on logged this morning.

Master is affect


> SECURITY: Fix an out of-bound read access in the packet handling code.
> Reported by Ben Hawkes
> https://anongit.mindrot.org/openssh.git/commit/?id=2fecfd486bdba9f51b3a789277bb0733ca36e1c0

Use CVE-2016-1907.
Comment 3 Armin Kuster 2016-01-15 19:48:13 UTC
unfortunate I am getting fetch errors.

ERROR: Function failed: Fetcher failure for URL: 'ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-7.1p2.tar.gz'. Unable to fetch URL from any source.
ERROR: Logfile of failure stored in: /yocto/OE/maint/poky/build/tmp/work/core2-64-poky-linux/openssh/7.1p2-r0/temp/log.do_fetch.5930
ERROR: Task 5 (/yocto/OE/maint/poky/meta/recipes-connectivity/openssh/openssh_7.1p2.bb, do_fetch) failed with exit code '1'


the tarball does not exists on openbsd nor any of its mirrors.  maybe too soon.
Comment 4 Armin Kuster 2016-01-16 00:22:32 UTC
CVE-2016-1907: Master and Jethro patch sent
http://patches.openembedded.org/patch/112553/

Jethro was just updated for CVE-2016-0777 and CVE-2016-0778 by package update.
Comment 6 Armin Kuster 2016-01-16 01:01:30 UTC
new master and Jethro patch series sent.

http://patches.openembedded.org/patch/112555/
Comment 8 Alexandru Roman 2016-02-12 13:41:00 UTC
Verified.