Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 572048 - <net-misc/nxplayer-5.0.63.3: information leak vulnerability in OpenSSH client code (CVE-2016-{0777,0778})
Summary: <net-misc/nxplayer-5.0.63.3: information leak vulnerability in OpenSSH client...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://www.nomachine.com/SU02N00100
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-16 00:58 UTC by Bernard Cafarelli
Modified: 2016-03-05 10:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bernard Cafarelli gentoo-dev 2016-01-16 00:58:25 UTC
From upstream:
Luxembourg, January 15th, 2016

NoMachine makes available updated packages to prevent an information
leak vulnerability in OpenSSH client code (CVE-2016-0777 and
CVE-2016-0778) which can allow a malicious server to read memory on
connecting computers, including private client user keys.

To prevent any possible exploit, NoMachine has released new software
packages for Windows, Linux and Mac OS X. Since the nxssh client may be
used in some connection configurations, we strongly advise all users of
version 5 to update their installations to 5.0.63. For further details
please consult our original security advisory here:
https://www.nomachine.com/SU02N00100.

net-misc/nxplayer includes the mentioned nxssh binary in the upstream advisory.
I bumped the package to fixed version 5.0.63.3 and removed the vulnerable ones (package is ~arch only)
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-03-05 10:46:37 UTC
Fixed package from upstream committed and all vulnerable versions removed per previous comment. openssh CVE vulnerabilities being tracked in bug 571892. Unstable so no GLSA.