REDHAT-BUG-2498179: Low severity libssh libssh vulnerability
A flaw was found in libssh username handling for ProxyCommand expansion. The sshcheckusernamesyntax() validation path in src/misc.c used an incomplete dangerous-character filter for usernames expanded through %r. As a result, specially crafted usernames containing shell-significant characters could reach shell-evaluated ProxyCommand handling and influence shell expansion, exposing environment variables and causing unintended shell behavior. This issue affects clients that combine untrusted username input with ProxyCommand-style shell execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2498179?
The severity of REDHAT-BUG-2498179 is classified as low.
How do I fix REDHAT-BUG-2498179?
To fix REDHAT-BUG-2498179, update your libssh software to the latest version that includes the relevant patches.
What is the risk associated with REDHAT-BUG-2498179?
The risk associated with REDHAT-BUG-2498179 is rated at 5, which indicates potential security concerns during usage.
What is the main issue reported in REDHAT-BUG-2498179?
The main issue reported in REDHAT-BUG-2498179 is an incomplete dangerous-character filter for usernames in ProxyCommand expansion.
What software is affected by REDHAT-BUG-2498179?
The affected software by REDHAT-BUG-2498179 is libssh.