Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61984

Опубликовано: 06 окт. 2025
Источник: redhat
CVSS3: 5.3

Описание

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

A flaw was found in OpenSSH where control characters in usernames were not properly validated when sourced from untrusted inputs like the command line or configuration expansion. If a ProxyCommand is used, these control characters could modify command behavior, potentially leading to code execution.

Отчет

The impact is MODERATE because it is a critical component used across many Red Hat products. The issue occurs only when a ProxyCommand is configured and the SSH client handles a username containing control characters from an untrusted source, such as script-generated input or expanded configuration values.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensshOut of support scope
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Enterprise Linux 10opensshFixedRHSA-2025:2347917.12.2025
Red Hat Enterprise Linux 10.0 Extended Update SupportopensshFixedRHSA-2026:167802.02.2026
Red Hat Enterprise Linux 8opensshFixedRHSA-2025:2348117.12.2025
Red Hat Enterprise Linux 8opensshFixedRHSA-2025:2348117.12.2025
Red Hat Enterprise Linux 9opensshFixedRHSA-2025:2348017.12.2025
Red Hat Enterprise Linux 9opensshFixedRHSA-2025:2348017.12.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-159
https://bugzilla.redhat.com/show_bug.cgi?id=2401960openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.6
ubuntu
12 месяцев назад

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

CVSS3: 3.6
nvd
12 месяцев назад

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

CVSS3: 3.6
msrc
12 месяцев назад

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

CVSS3: 3.6
debian
12 месяцев назад

ssh in OpenSSH before 10.1 allows control characters in usernames that ...

suse-cvrf
11 месяцев назад

Security update for openssh

5.3 Medium

CVSS3