#VU84789 OS Command Injection in OpenSSH - CVE-2023-51385
Published: December 26, 2023 / Updated: November 8, 2024
OpenSSH
OpenSSH
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing user names, if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. A remote attacker can execute arbitrary OS commands via an untrusted Git repository.
Remediation
External links
- https://www.openssh.com/txt/release-9.6
- https://www.openwall.com/lists/oss-security/2023/12/18/2
- https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a
- https://www.debian.org/security/2023/dsa-5586
- https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
- http://www.openwall.com/lists/oss-security/2023/12/26/4