Bug 8935 - OpenSSH client: CVE-2016-0777, CVE-2016-0778 and CVE-2016-1907
Summary: OpenSSH client: CVE-2016-0777, CVE-2016-0778 and CVE-2016-1907
Status: VERIFIED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: 2.0.1
Hardware: x86 Multiple
: High normal
Target Milestone: 2.0.2
Assignee: Armin Kuster
QA Contact: Alexandru Roman
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2016-01-15 18:47 UTC by Armin Kuster
Modified: 2016-02-12 13:41 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Armin Kuster 2016-01-15 18:47:25 UTC
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature 

CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
Comment 1 Armin Kuster 2016-01-15 18:50:26 UTC
Master package was updated to 7.1p2

http://cgit.openembedded.org/openembedded-core/commit/?id=b3b679d5be86f73d1a06c7230cb00872f0a407b5

Jethro is at version 7.1.p1 so cherry-picking this should be ok.

Fido needs patches.. working on them.
Comment 2 Armin Kuster 2016-01-15 18:53:25 UTC
new on logged this morning.

Master is affect


> SECURITY: Fix an out of-bound read access in the packet handling code.
> Reported by Ben Hawkes
> https://anongit.mindrot.org/openssh.git/commit/?id=2fecfd486bdba9f51b3a789277bb0733ca36e1c0

Use CVE-2016-1907.
Comment 3 Armin Kuster 2016-01-15 19:48:13 UTC
unfortunate I am getting fetch errors.

ERROR: Function failed: Fetcher failure for URL: 'ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-7.1p2.tar.gz'. Unable to fetch URL from any source.
ERROR: Logfile of failure stored in: /yocto/OE/maint/poky/build/tmp/work/core2-64-poky-linux/openssh/7.1p2-r0/temp/log.do_fetch.5930
ERROR: Task 5 (/yocto/OE/maint/poky/meta/recipes-connectivity/openssh/openssh_7.1p2.bb, do_fetch) failed with exit code '1'


the tarball does not exists on openbsd nor any of its mirrors.  maybe too soon.
Comment 4 Armin Kuster 2016-01-16 00:22:32 UTC
CVE-2016-1907: Master and Jethro patch sent
http://patches.openembedded.org/patch/112553/

Jethro was just updated for CVE-2016-0777 and CVE-2016-0778 by package update.
Comment 6 Armin Kuster 2016-01-16 01:01:30 UTC
new master and Jethro patch series sent.

http://patches.openembedded.org/patch/112555/
Comment 8 Alexandru Roman 2016-02-12 13:41:00 UTC
Verified.