ELSA-2024-1130

ELSA-2024-1130 - openssh security update

Type:SECURITY
Severity:MODERATE
Release Date:2024-03-06

Description


[8.7p1-34.3]
- Fix Terrapin attack (CVE-2023-48795)
Resolves: RHEL-19764
- Forbid shell metasymbols in username/hostname (CVE-2023-51385)
Resolves: RHEL-19822


Related CVEs


CVE-2023-48795
CVE-2023-51385

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) openssh-8.7p1-34.el9_3.3.src.rpm310905a7329f67168b38c85711e3c000-ol9_aarch64_appstream
openssh-8.7p1-34.el9_3.3.src.rpm310905a7329f67168b38c85711e3c000-ol9_aarch64_baseos_latest
openssh-8.7p1-34.el9_3.3.aarch64.rpmad08868c0d78e1cced360cff9d679410-ol9_aarch64_baseos_latest
openssh-askpass-8.7p1-34.el9_3.3.aarch64.rpmf435eed28f334b1bcb21972e7ceacb64-ol9_aarch64_appstream
openssh-clients-8.7p1-34.el9_3.3.aarch64.rpm31991d9e054beff3086f16082e4b8e03-ol9_aarch64_baseos_latest
openssh-keycat-8.7p1-34.el9_3.3.aarch64.rpm789fdfbcb87a121833be246d24256b69-ol9_aarch64_baseos_latest
openssh-server-8.7p1-34.el9_3.3.aarch64.rpm19a7b2ec1a6c17c393db5b88e9afbcb3-ol9_aarch64_baseos_latest
pam_ssh_agent_auth-0.10.4-5.34.el9_3.3.aarch64.rpm07d0bb3a67603132662000db01117ae6-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) openssh-8.7p1-34.el9_3.3.src.rpm310905a7329f67168b38c85711e3c000-ol9_x86_64_appstream
openssh-8.7p1-34.el9_3.3.src.rpm310905a7329f67168b38c85711e3c000-ol9_x86_64_baseos_latest
openssh-8.7p1-34.el9_3.3.x86_64.rpm9c8cea2dbf1524002c028ef9eea994db-ol9_x86_64_baseos_latest
openssh-askpass-8.7p1-34.el9_3.3.x86_64.rpma7ad6996d7d7526a1179e37711d38285-ol9_x86_64_appstream
openssh-clients-8.7p1-34.el9_3.3.x86_64.rpm28457aa1a5525ebf48cc52c31ecb6fd5-ol9_x86_64_baseos_latest
openssh-keycat-8.7p1-34.el9_3.3.x86_64.rpmaaed8f78a32c8a896267c2ecadbaa901-ol9_x86_64_baseos_latest
openssh-server-8.7p1-34.el9_3.3.x86_64.rpm1ed55ec78b50ec7532fe340b124a2f41-ol9_x86_64_baseos_latest
pam_ssh_agent_auth-0.10.4-5.34.el9_3.3.x86_64.rpmf6134c03e674f3cc3018c6b3588dc89e-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete