• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM Patches OpenSSH Security Flaws That Impact IBM i

    February 8, 2016 Alex Woodie

    IBM last week patched another pair of security vulnerabilities in the OpenSSH client for IBM i. The security flaws, which impact all current releases of IBM i–and very likely older releases that are no longer under maintenance–carry a moderate to severe risk, and could be used to execute arbitrary code on an IBM i server, obtain private cryptographic security keys, or execute a denial of service attack, IBM says.

    On February 1, IBM issued a security bulletin to address the two flaws in its OpenSSH implementation for IBM i. Both flaws stem from a poor design in the OpenSSH client roaming feature that makes it susceptible to leaking information and buffer overflow attacks.

    The first flaw, which is identified as CVE-2016-0777, by the Common Vulnerabilities and Exposures database, carries a CVSS base score of 6.5, which makes it a medium-to-severe threat. The fact that this vulnerability can come across the network, requires no privileges, and is relatively uncouple make this vulnerability potentially dangerous, according to IBM’s X-Force report on the flaw.

    This flaw is susceptible to “information leakage” when the contents of a buffer are requested for retransmission. “OpenSSH could allow a remote attacker to obtain sensitive information, caused by a client information leak from using the roaming connection feature,” IBM says. “By persuading a victim to connect to a malicious server, an attacker could exploit this vulnerability to retrieve private cryptographic keys or other sensitive information.”

    The second flaw, which is identified as CVE-2016-0778 by the CVE database, carries a CVSS base score of 5, which makes it a medium threat. This score is lower than the first flaw because while this attack does come over the network and doesn’t require privileges on the part of the attacker, it is a relatively complex attack mechanism, according to the X-Force report.

    IBM says this flaw makes OpenSSH vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the API. “By persuading a victim to connect to a malicious server, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash,” IBM says.

    Like most enterprise IT companies, IBM announced security flaws publicly only after it has patched them, and this time is no different. Big Blue has issued three emergency PTFs to address the problems with the OpenSSH client. The PTF for IBM i version 6.1, 7.1., and 7.2 are SI59305, SI59213, and SI59204, respectively.

    OpenSSH was created by the OpenBSD team as an alternative to the original Secure Shell (SSH) software, which is proprietary. OpenSSH and SSH provide encrypted protocols to enable people to remotely log in to servers over unsecured networks. SSH and OpenSSH are often viewed as more secure than SSL (Secure Sockets Layer) and TLS (Transport Layer Security) encryption protocols, and have been widely adopted in recent years. SSL, and in particular OpenSSL, have suffered from security problems recently, in particular the infamous Heartbleed vulnerability that afflicted OpenSSL in 2014 that potentially exposed millions of passwords.

    The new OpenSSH flaws impact OpenSSH version 7.1p2, which was released January 14 and addresses the two security flaws in the roaming feature. Apparently, the roaming feature was not a fully supported feature, but somebody found a way to hack it anyway.

    To read the IBM security vulnerability, see www-01.ibm.com/support/docview.wss?uid=nas8N1021109.

    RELATED STORIES

    IBM Tops List of Security Vulnerabilities, But What Does It Mean?

    Keeping Up With Security Threats To IBM i

    State of IBM i Security? Still Horrible, After All These Years

    Heartbleed, OpenSSL, and IBM i: What You Need to Know

    IBM And ISVs Fight POODLE Vulnerability In SSL 3.0

    Heartbleed Exposes The Vulnerability Of An IBM i Mentality

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    COMMON:  2016 Annual Meeting & Expo, May 15 - 18, in New Orleans! Great Power Systems event!
    System i Developer:  RPG & DB2 Summit - March 22-24 in Dallas. Register by Feb 12 and save $300!
    BCD:  IBM i eBook: Top 10 Reasons to Choose PHP. Download now »

    Coding Is Never Without A Reason; PHP Has 10 IBM i and .Net Connectivity With XMLSERVICE

    Leave a Reply Cancel reply

Volume 26, Number 06 -- February 8, 2016
THIS ISSUE SPONSORED BY:

New Generation Software
Fresche Legacy
System i Developer
Linoma Software
Storagepipe

Table of Contents

  • Where’s MKS Implementer? Alive and Well At PTC
  • The Jobs Of The People Who Make IBM i Platforms Work
  • From Green Screens To Web Services: An ROI Story
  • App Dev Evolution Opens Doors For Midrange Dynamics
  • IBM Patches OpenSSH Security Flaws That Impact IBM i

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • What You Will Find In IBM i 7.6 TR1 and IBM i 7.5 TR7
  • Three Things For IBM i Shops To Consider About DevSecOps
  • Big Blue Converges IBM i RPG And System Z COBOL Code Assistants Into “Project Bob”
  • As I See It: Retirement Challenges
  • IBM i PTF Guide, Volume 27, Number 41
  • Stacking Up Power11 Entry Server Performance To Older Iron
  • Big Blue Boosts IBM i Support In Instana, Adds Tracing
  • It Is Time To Tell Us What You Are Thinking And Doing
  • IBM i PTF Guide, Volume 27, Number 40
  • The GenAI Boom Is Only Slightly Louder Than The Dot Com Boom

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle