https://seclists.org/oss-sec/2024/q3/20: Announce: OpenSSH 9.8 leased
Published Jul 3, 2024
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH
Frequently Asked Questions
1
What is CVE-2024-39894?
CVE-2024-39894 is a vulnerability in OpenSSH related to a logic error in the ssh(1) command concerning ObscureKeystrokeTiming.
2
What systems are affected by CVE-2024-39894?
CVE-2024-39894 affects versions of OpenSSH that exhibit the specified logic error.
3
How do I fix CVE-2024-39894?
To fix CVE-2024-39894, update your OpenSSH installation to the latest version provided by the maintainers.
4
What is the severity of CVE-2024-39894?
The severity of CVE-2024-39894 can vary based on its exploitation potential, but it should be assessed according to your environment's specific security policies.
5
When was CVE-2024-39894 published?
CVE-2024-39894 was published on July 3, 2024.