[CLSA-2024:1709562468] Fix CVE(s): CVE-2023-6004, CVE-2023-6918
Type:
security
Severity:
Moderate
Release date:
2024-03-04 14:27:52 UTC
Description:
* SECURITY UPDATE: ProxyCommand/ProxyJump features allow injection of malicious code through hostname - debian/patches/CVE-2023-6004-pre1.patch: move common parser functions to config_parser.c - debian/patches/CVE-2023-6004-pre2.patch: prevent possible segmentation fault - debian/patches/CVE-2023-6004-02.patch: allow multiple '@' in usernames - debian/patches/CVE-2023-6004-03.patch: simplify the hostname parsing in ssh_options_set - debian/patches/CVE-2023-6004-04.patch: add function to check allowed characters of a hostname - debian/patches/CVE-2023-6004-05.patch: add test for ssh_check_hostname_syntax - debian/patches/CVE-2023-6004-06.patch: check for valid syntax of a hostname if it is a domain name - debian/patches/CVE-2023-6004-07.patch: add test for proxycommand injection - debian/patches/CVE-2023-6004-08.patch: add test for ssh_is_ipaddr - debian/patches/CVE-2023-6004-09.patch: add ipv6 link-local check for an ip address - debian/patches/CVE-2023-6004-10.patch: add tests for ipv6 link-local - debian/patches/CVE-2023-6004-regression1.patch: fix regression in IPv6 addresses in hostname parsing - debian/patches/CVE-2023-6004-regression2.patch: increase test coverage for IPv6 address parsing as hostnames - CVE-2023-6004 * SECURITY UPDATE: Unchecked return values for digests may cause DoS - debian/patches/CVE-2023-6918-1.patch: systematically check return values when calculating digests - debian/patches/CVE-2023-6918-2.patch: detect context init failures - debian/patches/CVE-2023-6918-3.patch: code coverage for ssh_get_pubkey_hash() - CVE-2023-6918
Updated packages:
  • libssh-4_0.6.3-4.3ubuntu0.6+tuxcare.els1_amd64.deb
    sha:7663d07aae408e87523e2b56143c35aadc7dff86
  • libssh-dev_0.6.3-4.3ubuntu0.6+tuxcare.els1_amd64.deb
    sha:ba0c87366a92d25be72b1690d04bde758ceb4868
  • libssh-doc_0.6.3-4.3ubuntu0.6+tuxcare.els1_all.deb
    sha:db15cd41681ceae93d675eb8ff69ca17818ebaa2
  • libssh-gcrypt-4_0.6.3-4.3ubuntu0.6+tuxcare.els1_amd64.deb
    sha:6f95b9b58f0696bce454cc85f05cc9b81ac74039
  • libssh-gcrypt-dev_0.6.3-4.3ubuntu0.6+tuxcare.els1_amd64.deb
    sha:63985f215e124c3c2b852d339ef3d82ebd3dad40
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.