Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

Ubuntu 13.10 USN-2014-1 Moderate: OpenSSH Arbitrary Code Execution

ubuntu
Calendar Grey November 8, 2013
Scroller Ubuntu
Enhance your OpenSSH version to address potential vulnerabilities associated with the execution of unsolicited code stemming from malicious network packets.
OpenSSH could be made to run programs if it received specially crafted network traffic from an authenticated user.

Summary

OpenSSH could be made to run programs if it received specially crafted

network traffic from an authenticated user.

Software Description:

- openssh: secure shell (SSH) client, for secure access to remote machines

Details:

Markus Friedl discovered that OpenSSH incorrectly handled memory when the

AES-GCM cipher was used. A remote authenticated attacker could use this

issue to execute arbitrary code as their user, possibly bypassing

shell or command restrictions.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  openssh-server                  1:6.2p2-6ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2014-1

CVE-2013-4548

Severity
important
Lowest
Low
Medium
High
Critical

November 08, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.