CVE-2016-10012: Buffer Overflow
It was found that the shared memory manager used by pre-authentication compression support had a bounds checks that could be elided by some optimising compilers. Additionally, this memory manager was incorrectly accessible when pre-authentication compression was disabled. This could potentially allow attacks against the privileged monitor process from the sandboxed privilege-separation process (a compromise of the latter would be required first).
CVE assignment:
http://seclists.org/oss-sec/2016/q4/708
External References:
https://www.openssh.com/txt/release-7.4
Other sources
The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the mzback and mzlib data structures.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/opensshto a version that resolves this vulnerability.Fixed in 7.4 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u3Fixed in 1:8.4p1-5+deb11u7Fixed in 1:9.2p1-2+deb12u10Fixed in 1:9.2p1-2+deb12u9Fixed in 1:10.0p1-7+deb13u4Fixed in 1:10.0p1-7+deb13u2Fixed in 1:10.3p1-4 - Upgrade
Upgrade
OpenSSHto a version that resolves this vulnerability.Fixed in 7.4 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u3 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u7 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:9.2p1-2+deb12u10 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:9.2p1-2+deb12u9 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.0p1-7+deb13u4 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.0p1-7+deb13u2 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.3p1-4
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10012?
CVE-2016-10012 has a medium severity rating due to its potential to expose memory vulnerabilities.
How do I fix CVE-2016-10012?
To fix CVE-2016-10012, upgrade your OpenSSH package to at least version 7.4 for Red Hat and the specified versions for Ubuntu and Debian.
What vulnerability does CVE-2016-10012 address?
CVE-2016-10012 addresses a potential security flaw in the shared memory manager used by OpenSSH that could be exploited when pre-authentication compression is enabled.
Which versions of OpenSSH are affected by CVE-2016-10012?
CVE-2016-10012 affects OpenSSH versions prior to 7.4 for Red Hat and other corresponding versions for Ubuntu and Debian.
Is CVE-2016-10012 a critical vulnerability?
CVE-2016-10012 is not classified as critical but requires prompt attention due to its potential security implications.