安全公告详情

NS-SA-2022-0070

2022-05-08 20:41:39

简介

moderate: NetworkManager/openssh security update

严重级别

moderate

主题

An update for NetworkManager/openssh is now available for NewStart CGSL MAIN 6.02.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

NetworkManager: This package provides debug information for package NetworkManager-ppp. Debug information is useful when developing applications that use this package or when debugging this package.
openssh: This package provides debug information for package openssh. Debug information is useful when developing applications that use this package or when debugging this package.


Security Fix(es):
NetworkManager: An exploitable denial of service vulnerability exists in systemd which does not fully implement RFC3203, as it does not support authentication of FORCERENEW packets. A specially crafted DHCP FORCERENEW packet can cause a system, running the DHCP client, to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHPACK packets to reconfigure the system with arbitrary network settings.(CVE-2020-13529)
NetworkManager: bugfix
openssh: A flaw was found in OpenSSH. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user. Depending on system configuration, inherited groups may allow AuthorizedKeysCommand/AuthorizedPrincipalsCommand helper programs to gain unintended privileges, potentially leading to local privilege escalation.(CVE-2021-41617)
openssh: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.02.A0B5.

影响组件

  • NetworkManager
  • openssh

影响产品

  • CGSL MAIN 6.02

更新包

{"fix":[{"product":"CGSL MAIN 6.02","pkgs":[{"binary":["NetworkManager-1.32.10-4.el8.x86_64.rpm","NetworkManager-libnm-1.32.10-4.el8.x86_64.rpm","NetworkManager-ovs-1.32.10-4.el8.x86_64.rpm","NetworkManager-team-1.32.10-4.el8.x86_64.rpm","NetworkManager-tui-1.32.10-4.el8.x86_64.rpm","NetworkManager-wifi-1.32.10-4.el8.x86_64.rpm"],"source":"NetworkManager-1.32.10-4.el8.src.rpm"},{"binary":["openssh-8.5p1-2.el8.cgslv6_2.9.gedf8db5.x86_64.rpm","openssh-askpass-8.5p1-2.el8.cgslv6_2.9.gedf8db5.x86_64.rpm","openssh-clients-8.5p1-2.el8.cgslv6_2.9.gedf8db5.x86_64.rpm","openssh-server-8.5p1-2.el8.cgslv6_2.9.gedf8db5.x86_64.rpm"],"source":"openssh-8.5p1-2.el8.cgslv6_2.9.gedf8db5.src.rpm"}]}]}

CVE

参考