All errata/sisyphus_riscv64/ALT-PU-2024-9874-1
ALT-PU-2024-9874-1

Package update openssh in branch sisyphus_riscv64

Version9.6p1-alt2
Task#0
Published2024-07-11
Max severityCRITICAL
Severity:

Closed issues (2)

BDU:2024-04914
CRITICAL9.0

Уязвимость сервера средства криптографической защиты OpenSSH, позволяющая нарушителю выполнить произвольный код

Published: 2024-07-01Modified: 2026-04-22
CVSS 3.xCRITICAL 9.0
CVSS:3.x/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.0HIGH 7.6
CVSS:2.0/AV:N/AC:H/Au:N/C:C/I:C/A:C
References
CVE-2024-6387
HIGH8.1

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Published: 2024-07-01Modified: 2025-09-30
CVSS 3.xHIGH 8.1
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
References