[USN-6242-1] OpenSSH vulnerability
marc.deslauriers at canonical.com
Mon Jul 24 18:52:33 UTC 2023
Ubuntu Security Notice USN-6242-1
July 24, 2023
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
OpenSSH could be made to run programs as your login when using ssh-agent
- openssh: secure shell (SSH) for secure access to remote machines
It was discovered that OpenSSH incorrectly handled loading certain PKCS#11
providers. If a user forwarded their ssh-agent to an untrusted system, a
remote attacker could possibly use this issue to load arbitrary libraries
from the user's system and execute arbitrary code.
The problem can be corrected by updating your system to the following
Ubuntu 22.04 LTS:
Ubuntu 20.04 LTS:
In general, a standard system update will make all the necessary changes.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: OpenPGP digital signature
More information about the ubuntu-security-announce