Ubuntu Security Update USN-6592-1: libssh vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,903
Reaction score
75
Credits
-1,257
It was discovered that libssh incorrectly handled the ProxyCommand and the ProxyJump features. A remote attacker could possibly use this issue to inject malicious code into the command of the features mentioned through the hostname parameter. (CVE-2023-6004) It was discovered that libssh incorrectly handled return codes when performing message digest operations. A remote attacker could possibly use this issue to cause libssh to crash, obtain sensitive information, or execute arbitrary code. (CVE-2023-6918)

Continue reading...
 


Follow Linux.org

Members online


Top