USN-6560-3: OpenSSH vulnerability
USN-6560-2 fixed a vulnerability in OpenSSH. This update provides the corresponding update for Ubuntu 16.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled user names or host names with shell metacharacters. An attacker could possibly use this issue to perform OS command injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6560-3?
The severity of USN-6560-3 is classified as high due to potential exploitation by attackers.
How do I fix USN-6560-3?
To fix USN-6560-3, update the OpenSSH package to version 1:7.2p2-4ubuntu2.10+esm6 on Ubuntu 16.04 LTS.
What vulnerabilities does USN-6560-3 address?
USN-6560-3 addresses a vulnerability where OpenSSH incorrectly handled user names or host names with shell metacharacters.
Which software versions are affected by USN-6560-3?
The affected software versions for USN-6560-3 include OpenSSH client and server versions prior to 1:7.2p2-4ubuntu2.10+esm6 on Ubuntu 16.04 LTS.
What should I do if I cannot update my system for USN-6560-3?
If you cannot update for USN-6560-3, you should review and harden your SSH configurations to mitigate potential risks.