SUSE-SU-2016:1386-1

Advisory lineage Upstream: 3 Downstream: 0
Published: 23 May 2016, 15:04
Last modified:04 Feb 2026, 02:40

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 May 2016, 15:04
Published
Vulnerability first disclosed
04 Feb 2026, 02:40
Last Modified
Vulnerability information updated

Description

Security update for openssh This update for OpenSSH fixes three security issues. These security issues were fixed: - CVE-2016-3115: Sanitise input for xauth(1) (bsc#970632) - CVE-2016-1908: Prevent X11 SECURITY circumvention when forwarding X11 connections (bsc#962313) - CVE-2015-8325: Ignore PAM environment when using login (bsc#975865) These non-security issues were fixed: - Fix help output of sftp (bsc#945493) - Restarting openssh with openssh-fips installed was not working correctly (bsc#945484) - Fix crashes when /proc is not available in the chroot (bsc#947458) - Correctly parse GSSAPI KEX algorithms (bsc#961368) - More verbose FIPS mode/CC related documentation in README.FIPS (bsc#965576, bsc#960414) - Fix PRNG re-seeding (bsc#960414, bsc#729190) - Disable DH parameters under 2048 bits by default and allow lowering the limit back to the RFC 4419 specified minimum through an option (bsc#932483, bsc#948902)

Affected Systems

  • suseopenssh-askpass-gnome&distro=SUSE Linux Enterprise Desktop 12

    < 6.6p1-42.1

  • suseopenssh-askpass-gnome&distro=SUSE Linux Enterprise Desktop 12 SP1

    < 6.6p1-42.1

  • suseopenssh-askpass-gnome&distro=SUSE Linux Enterprise Server 12

    < 6.6p1-42.1

  • suseopenssh-askpass-gnome&distro=SUSE Linux Enterprise Server 12 SP1

    < 6.6p1-42.1

  • suseopenssh-askpass-gnome&distro=SUSE Linux Enterprise Server for SAP Applications 12

    < 6.6p1-42.1

  • suseopenssh-askpass-gnome&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1

    < 6.6p1-42.1

  • suseopenssh&distro=SUSE Linux Enterprise Desktop 12

    < 6.6p1-42.1

  • suseopenssh&distro=SUSE Linux Enterprise Desktop 12 SP1

    < 6.6p1-42.1

  • suseopenssh&distro=SUSE Linux Enterprise Server 12

    < 6.6p1-42.1

  • suseopenssh&distro=SUSE Linux Enterprise Server 12 SP1

    < 6.6p1-42.1

  • suseopenssh&distro=SUSE Linux Enterprise Server for SAP Applications 12

    < 6.6p1-42.1

  • suseopenssh&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1

    < 6.6p1-42.1

References (16)