OpenSSH Authentication Bypass Vulnerabilities in Ubuntu Systems: Security Advisory USN-6859-1
Summary
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS Summary: OpenSSH could be made to bypass authentication and remotely access systems without proper credentials. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: It was discovered that OpenSSH incorrectly handled signal management. A remote attacker could use this issue to bypass authentication and remotely access systems without proper credentials.
Update Instructions
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS openssh-client 1:9.6p1-3ubuntu13.3 openssh-server 1:9.6p1-3ubuntu13.3 Ubuntu 23.10 openssh-client 1:9.3p1-1ubuntu3.6 openssh-server 1:9.3p1-1ubuntu3.6 Ubuntu 22.04 LTS openssh-client 1:8.9p1-3ubuntu0.10 openssh-server 1:8.9p1-3ubuntu0.10 In general, a standard system update will make all the necessary changes.
References
https://ubuntu.com/security/notices/USN-6859-1
CVE-2024-6387
Package Information
https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.3 https://launchpad.net/ubuntu/+source/openssh/1:9.3p1-1ubuntu3.6 https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.10