2023年7月25日星期二

OpenSSH Remote Code Execution Vulnerability

Release Date: 25 Jul 2023

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability was identified in OpenSSH. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

Exploitation requires the presence of specific libraries on the victim system.

Remote exploitation requires that the agent was forwarded to an attacker-controlled system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Version prior to OpenSSH 9.3p2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

The vendors have issued fixes:

 

https://www.openssh.com/txt/release-9.3p2

 
 
 
 

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

惡意軟件警報 - 零售商成為 Scattered Spider 黑客組織勒索軟件攻擊的目標

惡意軟件警報 - 零售商成為 Scattered Spider 黑客組織勒索軟件攻擊的目標 發佈日期: 2025年05月02日 類別: ...