Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-7807

net-misc/openssh-8.1_p1-r1 - high and medium severity vulnerabilities

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Fixed
    • Icon: Normal Normal
    • None
    • None
    • None

      currently latest version of openssh in meta-repo (core-kit) is 8.1_p1-r1. It has two vulnerabilities:

      The client side in OpenSSH 5.7 through 8.3 has an Observable Discrepancy
      leading to an information leak in the algorithm negotiation.
      
      scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function
      (...)
      NOTE: the vendor reportedly has stated that they intentionally omit validation
      of "anomalous argument transfers" because that could "stand a great chance
      of breaking existing workflows."
      

            drobbins drobbins
            mrl5 mrl5
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: