USN-6560-2: OpenSSH vulnerabilities
USN-6560-1 fixed several vulnerabilities in OpenSSH. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: Fabian Bäumer, Marcus Brinkmann, Jörg Schwenk discovered that the SSH protocol was vulnerable to a prefix truncation attack. If a remote attacker was able to intercept SSH communications, extension negotiation messages could be truncated, possibly leading to certain algorithms and features being downgraded. This issue is known as the Terrapin attack. This update adds protocol extensions to mitigate this issue. (CVE-2023-48795) It was discovered that OpenSSH incorrectly handled user names or host names with shell metacharacters. An attacker could possibly use this issue to perform OS command injection. This only affected Ubuntu 18.04 LTS. (CVE-2023-51385)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6560-2?
USN-6560-2 addresses multiple vulnerabilities in OpenSSH, indicating a significant security risk if not patched.
How do I fix USN-6560-2?
To fix USN-6560-2, update OpenSSH to the specified versions: 1:7.6p1-4ubuntu0.7+esm3 for Ubuntu 18.04 and 1:7.2p2-4ubuntu2.10+esm5 for Ubuntu 16.04.
Which versions of OpenSSH are affected by USN-6560-2?
USN-6560-2 affects OpenSSH versions 1:7.6p1-4ubuntu0.7+esm3 and 1:7.2p2-4ubuntu2.10+esm5 on Ubuntu 18.04 and Ubuntu 16.04 respectively.
What products are impacted by USN-6560-2?
USN-6560-2 impacts the OpenSSH client and server on both Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Is USN-6560-2 relevant for both Ubuntu 16.04 LTS and Ubuntu 18.04 LTS?
Yes, USN-6560-2 provides security updates for both Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.