[CLSA-2022:1656959440] Fixed CVE-2016-10009 in openssh-5.3p1
Type:
security
Severity:
Important
Release date:
2022-07-04
Description:
- CVE-2016-10009: add whitelist of paths which may ssh-agent load from in order to prevent execution of arbitrary local pkcs#11
Updated packages:
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els1.x86_64.rpm
    sha:60ce7e232d04b7944e48ccb9ba617ff94ff36ece
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els1.i686.rpm
    sha:70e2879020a1c3986e13e6bb2778294f7710b38e
  • openssh-ldap-5.3p1-125.el6.tuxcare.els1.x86_64.rpm
    sha:2811096bca4b47cd59866818ab2f907468e65f37
  • openssh-clients-5.3p1-125.el6.tuxcare.els1.x86_64.rpm
    sha:e8b2d41f85cfb68c9be0b0c590a1594c7d8f26d9
  • openssh-askpass-5.3p1-125.el6.tuxcare.els1.x86_64.rpm
    sha:c71fcd8d4aeef2071df109dc6f1225b6eb39130e
  • openssh-5.3p1-125.el6.tuxcare.els1.x86_64.rpm
    sha:b4b815e576cf4b1383117132e56c1ac7eba4b0c4
  • openssh-server-5.3p1-125.el6.tuxcare.els1.x86_64.rpm
    sha:94ae763b491ca99102a9b9d7f41eeb5469703eff
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.