Security features bypass in OpenSSH - #VU71772

 

Security features bypass in OpenSSH - #VU71772

Published: February 2, 2023


Vulnerability identifier: #VU71772
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to a logic error when parsing the PermitRemoteOpen option. The PermitRemoteOpen option would ignore its first argument unless it was one of the special keywords "any" or "none", causing the permission list to fail open if only one permission was specified.


Affected software

OpenSSH
Slackware Linux
openssh

Remediation

Install updates from vendor's website.

OpenSSH - update to 9.2p1
openssh - update to 9.2p1

External References

Related Security Bulletins