MGASA-2021-0561 - Updated openssh packages fix security vulnerability

Publication date: 19 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0561.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-41617

Updated openssh packages fix security vulnerability:

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default
configurations are used, allows privilege escalation because supplemental
groups are not initialized as expected. Helper programs for
AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with
privileges associated with group memberships of the sshd process, if the
configuration specifies running the command as a different user
(CVE-2021-41617).

References:
- https://bugs.mageia.org/show_bug.cgi?id=29517
- https://www.openwall.com/lists/oss-security/2021/09/26/1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41617

SRPMS:
- 8/core/openssh-8.4p1-2.2.mga8

Mageia 2021-0561: openssh security update

Updated openssh packages fix security vulnerability: sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation beca...

Summary

Updated openssh packages fix security vulnerability:
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user (CVE-2021-41617).

References

- https://bugs.mageia.org/show_bug.cgi?id=29517

- https://www.openwall.com/lists/oss-security/2021/09/26/1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41617

Resolution

MGASA-2021-0561 - Updated openssh packages fix security vulnerability

SRPMS

- 8/core/openssh-8.4p1-2.2.mga8

Severity
Publication date: 19 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0561.html
Type: security
CVE: CVE-2021-41617

Related News