[CLSA-2023:1703610859] Fix CVE(s): CVE-2023-51385
Type:
security
Severity:
Critical
Release date:
2023-12-26 17:14:23 UTC
Description:
* SECURITY UPDATE: possible OS command injection - debian/patches/CVE-2023-51385.patch: ban user/hostnames with most shell metacharacters in command line - CVE-2023-51385
Updated packages:
  • openssh-client_7.6p1-4ubuntu0.7+tuxcare.els4_amd64.deb
    sha:184bd21c72ade183f0cd0e491a361273d2921941
  • openssh-server_7.6p1-4ubuntu0.7+tuxcare.els4_amd64.deb
    sha:42ac91ad5733239fc9b00bb2d8f849e6a1909dcb
  • openssh-sftp-server_7.6p1-4ubuntu0.7+tuxcare.els4_amd64.deb
    sha:fbdf0d28382c570a5fd877a905e0c620baf8170a
  • ssh_7.6p1-4ubuntu0.7+tuxcare.els4_all.deb
    sha:3f00a7ef956e276ccac859e364598b8f6cb8e380
  • ssh-askpass-gnome_7.6p1-4ubuntu0.7+tuxcare.els4_amd64.deb
    sha:dcb9df21b71c67ec83861a021b54f6ff700cf664
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.