USN-7443-2: Erlang vulnerability
USN-7443-1 fixed a vulnerability in Erlang. This update provides the corresponding update for Ubuntu 25.04. Original advisory details: Fabian Bäumer, Marcel Maehren, Marcus Brinkmann, and Jörg Schwenk discovered that Erlang OTP’s SSH module incorrect handled authentication. A remote attacker could use this issue to execute arbitrary commands without authentication, possibly leading to a system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7443-2?
The severity of USN-7443-2 is high due to incorrect handling of authentication in Erlang OTP's SSH module.
How do I fix USN-7443-2?
To fix USN-7443-2, upgrade to the patched version 1:27.3+dfsg-1ubuntu1.1 for the erlang and erlang-ssh packages.
Which versions are affected by USN-7443-2?
USN-7443-2 affects the erlang and erlang-ssh packages in Ubuntu version 25.04 prior to the fix.
Who discovered the vulnerability in USN-7443-2?
The vulnerability in USN-7443-2 was discovered by Fabian Bäumer, Marcel Maehren, Marcus Brinkmann, and Jörg Schwenk.
What does USN-7443-2 address?
USN-7443-2 addresses a vulnerability related to the SSH module in Erlang OTP that improperly handled authentication.