Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2024:0140-2 critical: libssh command injection fix

suse
Calendar Grey January 18, 2024
Dist Suse Esm H88
This important system upgrade tackles major flaws in OpenSSL, enhancing protection from cyber risks.
* bsc#1211188 * bsc#1211190 * bsc#1218126 * bsc#1218186 * bsc#1218209

Summary

## This update for libssh fixes the following issues: Security fixes: * CVE-2023-6004: Fixed command injection using proxycommand (bsc#1218209) * CVE-2023-48795: Fixed potential downgrade attack using strict kex (bsc#1218126) * CVE-2023-6918: Fixed missing checks for return values of MD functions (bsc#1218186) * CVE-2023-1667: Fixed NULL dereference during rekeying with algorithm guessing (bsc#1211188) * CVE-2023-2283: Fixed possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190) Other fixes: * Update to version 0.9.8 * Allow @ in usernames when parsing from URI composes * Update to version 0.9.7 * Fix several memory leaks in GSSAPI handling code ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like

References

* bsc#1211188

* bsc#1211190

* bsc#1218126

* bsc#1218186

* bsc#1218209

Cross-

* CVE-2023-1667

* CVE-2023-2283

* CVE-2023-48795

* CVE-2023-6004

* CVE-2023-6918

CVSS scores:

* CVE-2023-1667 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

* CVE-2023-1667 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-2283 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2023-2283 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2023-48795 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2023-48795 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2023-6004 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

* CVE-2023-6004 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:0140-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here