Debian Security Update DSA-5724-1 openssh - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,872
Reaction score
74
Credits
-1,257
The Qualys Threat Research Unit (TRU) discovered that OpenSSH, an implementation of the SSH protocol suite, is prone to a signal handler race condition. If a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd's SIGALRM handler is called asynchronously and calls various functions that are not async-signal-safe. A remote unauthenticated attacker can take advantage of this flaw to execute arbitrary code with root privileges. This flaw affects sshd in its default configuration.
Details can be found in the Qualys advisory at https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
https://security-tracker.debian.org/tracker/DSA-5724-1

Continue reading...
 


Follow Linux.org

Members online


Top