Описание
ELSA-2024-1130: openssh security update (MODERATE)
[8.7p1-34.3]
- Fix Terrapin attack (CVE-2023-48795) Resolves: RHEL-19764
- Forbid shell metasymbols in username/hostname (CVE-2023-51385) Resolves: RHEL-19822
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
openssh
8.7p1-34.el9_3.3
openssh-askpass
8.7p1-34.el9_3.3
openssh-clients
8.7p1-34.el9_3.3
openssh-keycat
8.7p1-34.el9_3.3
openssh-server
8.7p1-34.el9_3.3
pam_ssh_agent_auth
0.10.4-5.34.el9_3.3
Oracle Linux x86_64
openssh
8.7p1-34.el9_3.3
openssh-askpass
8.7p1-34.el9_3.3
openssh-clients
8.7p1-34.el9_3.3
openssh-keycat
8.7p1-34.el9_3.3
openssh-server
8.7p1-34.el9_3.3
pam_ssh_agent_auth
0.10.4-5.34.el9_3.3
Связанные CVE
Связанные уязвимости
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.