IBM Support

Security Bulletin: Vulnerabilities in OpenSSH affect AIX (CVE-2018-20685 CVE-2018-6109 CVE-2018-6110 CVE-2018-6111)

Created by Roy St. John on
Published URL:
https://www.ibm.com/support/pages/node/872060
872060

Security Bulletin


Summary

Vulnerabilities in OpenSSH affect AIX.

Vulnerability Details

CVEID: CVE-2019-6109
DESCRIPTION: OpenSSH could allow a remote attacker to conduct spoofing attacks, caused by missing character encoding in the progress display. A man-in-the-middle attacker could exploit this vulnerability to spoof scp client output.
CVSS Base Score: 3.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/155488 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N)

CVEID: CVE-2019-6110
DESCRIPTION: OpenSSH could allow a remote attacker to conduct spoofing attacks, caused by accepting and displaying arbitrary stderr output from the scp server. A man-in-the-middle attacker could exploit this vulnerability to spoof scp client output.
CVSS Base Score: 3.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/155487 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N)

CVEID: CVE-2019-6111
DESCRIPTION: OpenSSH could allow a remote attacker to overwrite arbitrary files on the system, caused by missing received object name validation by the scp client. The scp implementation accepts arbitrary files sent by the server and a man-in-the-middle attacker could exploit this vulnerability to overwrite unrelated files.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/155486 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)

CVEID: CVE-2018-20685
DESCRIPTION: OpenSSH could allow a remote attacker to bypass security restrictions, caused by directory name validation by scp.c in the scp client. A man-in-the-middle attacker could exploit this vulnerability using the filename of . or an empty filename to bypass access restrictions and modify permissions of the target directory.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/155484 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected IBM Product VRMF
AIX 7.1
AIX 7.2
VIOS 2.2
VIOS 3.1
The following fileset levels are vulnerable:
Fileset Lower Level Upper Level
openssh.base.client 4.0.0.5200 7.5.102.1600
openssh.base.server 4.0.0.5200 7.5.102.1600
Note:  To determine if your system is vulnerable, execute the following commands:
lslpp -L | grep -i openssh.base.client
lslpp -L | grep -i openssh.base.server

Remediation/Fixes

FIXES
A fix is available for CVE-2018-20685, CVE-2019-6109, and CVE-2019-6111.
           
Please see the WORKAROUNDS AND MITIGATIONS section for mitigation steps in response to CVE-2019-6110.
           
To extract the fixes from the tar file:

zcat openssh-7.5.102.1800.tar.Z | tar xvf
Please refer to the Readme file to be aware of the changes that are part of the release.
IMPORTANT: If possible, it is recommended that a mksysb backup of the system be created.  Verify it is both bootable and readable before proceeding. Note that all the previously reported security vulnerability fixes are also included in above mentioned fileset level. Please refer to the readme file (provided along with the fileset) for the complete list of vulnerabilities fixed.
To preview the fix installation:
installp -apYd . openssh
To install the fix package:
installp -aXYd . openssh

Published advisory OpenSSH signature file location:
http://aix.software.ibm.com/aix/efixes/security/openssh_advisory13.asc.sig
https://aix.software.ibm.com/aix/efixes/security/openssh_advisory13.asc.sig
ftp://aix.software.ibm.com/aix/efixes/security/openssh_advisory13.asc.sig
openssl dgst -sha1 -verify [pubkey_file] -signature [advisory_file].sig [advisory_file]
openssl dgst -sha1 -verify [pubkey_file] -signature [ifix_file].sig [ifix_file]

Workarounds and Mitigations

The potential impact of CVE-2019-6110 may be mitigated by using the sftp command in place of the scp command.

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

None.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG10","label":"AIX"},"Component":"","Platform":[{"code":"PF002","label":"AIX"}],"Version":"7.1;7.2","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
16 July 2019

UID

ibm10872060