First published: Tue Apr 30 2024(Updated: )
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.<br>Security Fix(es):<br><li> libssh: ProxyCommand/ProxyJump features allow injection of malicious code through hostname (CVE-2023-6004)</li> <li> libssh: Missing checks for return values for digests (CVE-2023-6918)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.4 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libssh | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-config | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-debuginfo | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-debuginfo | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-debugsource | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-debugsource | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-devel | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-devel | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-debuginfo | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-debugsource | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh-devel | <0.10.4-13.el9 | 0.10.4-13.el9 |
redhat/libssh | <0.10.4-13.el9.aa | 0.10.4-13.el9.aa |
redhat/libssh-debuginfo | <0.10.4-13.el9.aa | 0.10.4-13.el9.aa |
redhat/libssh-debugsource | <0.10.4-13.el9.aa | 0.10.4-13.el9.aa |
redhat/libssh-devel | <0.10.4-13.el9.aa | 0.10.4-13.el9.aa |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | ||
Red Hat Enterprise Linux Server for IBM z Systems | ||
Red Hat Enterprise Linux 8 | ||
Red Hat Enterprise Linux for ARM 64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:2504 is classified as important.
You can resolve RHSA-2024:2504 by updating the affected libssh packages to version 0.10.4-13.el9 or later.
RHSA-2024:2504 addresses vulnerabilities including CVE-2023-6004 which allows code injection through hostname in ProxyCommand/ProxyJump features.
RHSA-2024:2504 affects multiple versions of Red Hat Enterprise Linux across architectures including x86_64, ARM 64, and Power.
Yes, the specific package version to upgrade to for resolving RHSA-2024:2504 is 0.10.4-13.el9.