https://seclists.org/oss-sec/2024/q3/50: CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems
Published Jul 11, 2024
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH
Frequently Asked Questions
1
What is the severity of CVE-2024-6387?
CVE-2024-6387 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-6387?
To fix CVE-2024-6387, update your OpenSSH package to the latest version provided for your Linux distribution.
3
What systems are affected by CVE-2024-6387?
CVE-2024-6387 affects OpenSSH servers running on glibc-based Linux systems.
4
Is there a workaround for CVE-2024-6387?
There are no specific workarounds for CVE-2024-6387; upgrading is the recommended mitigation.
5
What are the potential consequences of CVE-2024-6387 if exploited?
If exploited, CVE-2024-6387 could allow an attacker to execute arbitrary commands on the affected OpenSSH server.