Jeremy Brown discovered a flaw in the GSSAPI Key Exchange patch applied in Debian to OpenSSH, an implementation of the SSH protocol suite, affecting non-default configurations with the GSSAPIKeyExchange setting enabled. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code.
https://security-tracker.debian.org/tracker/DSA-6204-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6204-1
Continue reading...

