Lucene search

K
f5F5SOL20911042
HistoryMay 16, 2016 - 12:00 a.m.

SOL20911042 - OpenSSH vulnerability CVE-2015-8325

2016-05-1600:00:00
support.f5.com
166

0.0004 Low

EPSS

Percentile

5.1%

This previously described configuration is not the default configuration, and is a very unlikely sshdconfiguration on Red Hat Enterprise Linux.

Note the following:

  • The default sshdconfiguration uses UseLogin=no.
  • In Red Hat Enterprise Linux 6 and 7, configurations with UseLogin=yes do not work if you do not set SELinux to permissive mode, or disable SELinux.
  • While the default sshdPAM configuration uses the pam_env module, the system uses the module only to read system configuration files. The system does not, by default, enable you to read the userҀ™s**~/.pam_environment**.
  • In Red Hat Enterprise Linux 5 and earlier PAM versions, you cannot read userҀ™s environment settings, and you cannot exploit this issue on those versions.

Vulnerability Recommended Actions

If you are running a version listed in the Versions known to be vulnerable column, you can eliminate this vulnerability by upgrading to a version listed in theVersions known to be not vulnerable column. If the table lists only an older version than what you are currently running, or does not list a non-vulnerable version, then no upgrade candidate currently exists.

F5 responds to vulnerabilities in accordance with the Severity values published in the previous table. TheSeverity values and other security vulnerability parameters are defined in SOL4602: Overview of the F5 security vulnerability response policy.

BIG-IP

BIG-IP is not vulnerable to this issue in default configurations. F5 recommends that you do not modify the PAM configuration to enable the UseLogin feature.

BIG-IQ/Enterprise Manager

The BIG-IQ/Enterprise Manager systems are not vulnerable to this issue in default configurations. F5 recommends that you do not modify the PAM configuration to enable the UseLogin feature in the BIG-IQ/Enterprise Manager configurations.

Supplemental Information

  • SOL9970: Subscribing to email notifications regarding F5 products
  • SOL9957: Creating a custom RSS feed to view new and updated documents
  • SOL4918: Overview of the F5 critical issue hotfix policy
  • SOL167: Downloading software and firmware from F5
  • SOL13123: Managing BIG-IP product hotfixes (11.x - 12.x)
  • SOL10025: Managing BIG-IP product hotfixes (10.x)
  • SOL15106: Managing BIG-IQ product hotfixes
  • SOL15113: BIG-IQ hotfix matrix