[CLSA-2023:1691576279] Fix CVE(s): CVE-2023-38408
Type:
security
Severity:
Critical
Release date:
2023-08-09 10:18:03 UTC
Description:
* SECURITY UPDATE: helper programs can dlopen()/dlclose() any libraries from /usr/lib - debian/patches/CVE-2023-38408-Ensure-FIDO-PKCS11-libraries-contain-expect.patch: checks libraries before dlopen - debian/patches/CVE-2023-38408-Separate-ssh-pkcs11-helpers-for-each-p11-mo.patch: separate ssh-pkcs11-helpers for each p11 module - CVE-2023-38408
Updated packages:
  • openssh-client_7.2p2-4ubuntu2.10+tuxcare.els2_amd64.deb
    sha:66bb61df671c57faef19b182108e7d6c613a2a25
  • openssh-client-ssh1_7.2p2-4ubuntu2.10+tuxcare.els2_amd64.deb
    sha:7d7b8d068712ef334798515b02fadcb0fe7973e0
  • openssh-server_7.2p2-4ubuntu2.10+tuxcare.els2_amd64.deb
    sha:8788eabdbc4352ab3e1334d25615ed5e516a2aff
  • openssh-sftp-server_7.2p2-4ubuntu2.10+tuxcare.els2_amd64.deb
    sha:c0901e95b0a41fc6584449bb8bf4e3235093d6b1
  • ssh_7.2p2-4ubuntu2.10+tuxcare.els2_all.deb
    sha:9d109b9176260a4f26412502b6bec60f0352a83d
  • ssh-askpass-gnome_7.2p2-4ubuntu2.10+tuxcare.els2_amd64.deb
    sha:cb7c430c5629bed2e0fa017997bbb5a6cd2ac10c
  • ssh-krb5_7.2p2-4ubuntu2.10+tuxcare.els2_all.deb
    sha:be7e3ee15e1c0b75977cfc2119bd9ecde61965ba
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.