USN-6592-1: libssh vulnerabilities
It was discovered that libssh incorrectly handled the ProxyCommand and the ProxyJump features. A remote attacker could possibly use this issue to inject malicious code into the command of the features mentioned through the hostname parameter. (CVE-2023-6004) It was discovered that libssh incorrectly handled return codes when performing message digest operations. A remote attacker could possibly use this issue to cause libssh to crash, obtain sensitive information, or execute arbitrary code. (CVE-2023-6918)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6592-1?
The severity of USN-6592-1 is high due to the potential for remote code injection.
How do I fix USN-6592-1?
You can fix USN-6592-1 by updating the libssh package to the latest recommended version.
What systems are affected by USN-6592-1?
USN-6592-1 affects multiple versions of Ubuntu, including 20.04, 22.04, 23.04, and 23.10.
What are the vulnerabilities addressed in USN-6592-1?
USN-6592-1 addresses vulnerabilities related to the improper handling of ProxyCommand and ProxyJump in libssh.
Can a remote attacker exploit USN-6592-1?
Yes, a remote attacker could exploit USN-6592-1 to inject malicious code through the hostname parameter.