Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Debian 1:8.4p1-5 moderate: OpenSSH Command Injection Threat

debian
Calendar Grey December 22, 2023
Debian Logo
Crucial OpenSSH security patches released for Debian platforms addressing several weaknesses. Ensure your system is updated.
Several vulnerabilities have been discovered in OpenSSH, an implementation of the SSH protocol suite

Summary

CVE-2021-41617

It was discovered that sshd failed to correctly initialise
supplemental groups when executing an AuthorizedKeysCommand or
AuthorizedPrincipalsCommand, where a AuthorizedKeysCommandUser or
AuthorizedPrincipalsCommandUser directive has been set to run the
command as a different user. Instead these commands would inherit
the groups that sshd was started with.

CVE-2023-28531

Luci Stanescu reported that a error prevented constraints being
communicated to the ssh-agent when adding smartcard keys to the
agent with per-hop destination constraints, resulting in keys being
added without constraints.

CVE-2023-48795

Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that
the SSH protocol is prone to a prefix truncation attack, known as
the "Terrapin attack". This attack allows a MITM attacker to effect
a limited break of the integrity of the early encrypted SSH
transport protocol by sending extra messages prior to the
comme...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: openssh
CVE ID: CVE-2021-41617 CVE-2023-28531 CVE-2023-48795 CVE-2023-51384

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here