Security Guide
  • News
  • Security
  • Tech
  • Guides
  • Privacy
  • Resources
  • Reviews
  • Tools
    • Strong Password Generator
    • Personal Data Leak Checker
    • Password Leak Checker
    • VPN Speed Test
    • Website Vulnerability Scanner
  • More
    • Contact Us
    • About Us
    • Advertise
  • Privacy Policy
No Result
View All Result
  • News
  • Security
  • Tech
  • Guides
  • Privacy
  • Resources
  • Reviews
  • Tools
    • Strong Password Generator
    • Personal Data Leak Checker
    • Password Leak Checker
    • VPN Speed Test
    • Website Vulnerability Scanner
  • More
    • Contact Us
    • About Us
    • Advertise
  • Privacy Policy
No Result
View All Result
Security Guide - Cyber Security News Today - Latest News and Updates About Security
No Result
View All Result

New OpenSSH Vulnerability Exposes Linux Programs to Distant Command Injection 2023

SecurityGuide by SecurityGuide
July 25, 2023
in linux
0 0
0
New OpenSSH Vulnerability Exposes Linux Programs to Distant Command Injection 2023
0
SHARES
6
VIEWS
Share on FacebookShare on Twitter

New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

Particulars have emerged a couple of now-patched flaw in OpenSSH that may very well be doubtlessly exploited to run arbitrary instructions remotely on compromised hosts beneath particular situations.

“This vulnerability permits a distant attacker to doubtlessly execute arbitrary instructions on susceptible OpenSSH’s forwarded ssh-agent,” Saeed Abbasi, supervisor of vulnerability analysis at Qualys, said in an evaluation final week.

The vulnerability is being tracked beneath the CVE identifier CVE-2023-38408 (CVSS rating: N/A). It impacts all variations of OpenSSH earlier than 9.3p2.

OpenSSH is a well-liked connectivity instrument for distant login with the SSH protocol that is used for encrypting all site visitors to get rid of eavesdropping, connection hijacking, and different assaults.

Profitable exploitation requires the presence of sure libraries on the sufferer system and that the SSH authentication agent is forwarded to an attacker-controlled system. SSH agent is a background program that maintains customers’ keys in reminiscence and facilitates distant logins to a server with out having to enter their passphrase once more.

“Whereas searching by means of ssh-agent’s supply code, we observed {that a} distant attacker, who has entry to the distant server the place Alice’s ssh-agent is forwarded to, can load (dlopen()) and instantly unload (dlclose()) any shared library in /usr/lib* on Alice’s workstation (by way of her forwarded ssh-agent, whether it is compiled with ENABLE_PKCS11, which is the default),” Qualys defined.

The cybersecurity agency mentioned it was in a position to devise a profitable proof-of-concept (PoC) towards default installations of Ubuntu Desktop 22.04 and 21.10, though different Linux distributions are anticipated to be susceptible as nicely.

It’s strongly suggested that customers of OpenSSH replace to the latest model with the intention to safeguard towards potential cyber threats.

Earlier this February, OpenSSH maintainers released an replace to remediate a medium-severity safety flaw (CVE-2023-25136, CVSS rating: 6.5) that may very well be exploited by an unauthenticated distant attacker to modify unexpected memory locations and theoretically obtain code execution.

A subsequent launch in March addressed one other safety concern that may very well be abused by the use of a particularly crafted DNS response to carry out an out-of-bounds learn of adjoining stack information and trigger a denial-of- service to the SSH consumer.

Tags: Linux
Next Post

Cybersecurity basics for beginners: 2023 guide

SecurityGuide

SecurityGuide

SecurityGuide.net is a premier destination for comprehensive cybersecurity insights. As a dedicated security guide blog, we provide a curated collection of expertly crafted guides, up-to-date news, and practical tutorials. Our mission is to equip security researchers with the latest tools, techniques, and best practices, ensuring they stay ahead of cyber threats. Join our thriving community of professionals and enthusiasts and strengthen your cybersecurity prowess in this rapidly evolving digital landscape

Next Post

Cybersecurity basics for beginners: 2023 guide

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You might also like

Google Data Breach via Salesforce Hack: What You Need to Know

Google Data Breach via Salesforce Hack: What You Need to Know

August 10, 2025
The 12 Titans of Cybersecurity in 2024: Navigating the Evolving Digital Landscape

The 12 Titans of Cybersecurity in 2024: Navigating the Evolving Digital Landscape

January 19, 2024
Enhancing Account Security: GitHub Mandates Two-Factor Authentication (2FA)

Enhancing Account Security: GitHub Mandates Two-Factor Authentication (2FA)

January 19, 2024
Secure Online Account: A Comprehensive Guide To Account Security

Secure Online Account: A Comprehensive Guide To Account Security

October 17, 2023
Privacy Matters: Best Essential Steps To Safeguard Your Online Presence in 2023

Privacy Matters: Best Essential Steps To Safeguard Your Online Presence in 2023

October 17, 2023
How to perform a website security Audit? Here’s How To Know!

How to perform a website security Audit? Here’s How To Know!

October 17, 2023
Facebook Twitter Instagram Youtube

About Us

Security Guide – Cyber Security News Today – Latest News and Updates About Security

SecurityGuide.net is a premier destination for comprehensive cybersecurity insights. As a dedicated security guide blog, we provide a curated collection of expertly crafted guides, up-to-date news, and practical tutorials. Our mission is to equip security researchers with the latest tools, techniques, and best practices, ensuring they stay ahead of cyber threats. Join our thriving community of professionals and enthusiasts and strengthen your cybersecurity prowess in this rapidly evolving digital landscape.

Our Categories

  • Account Security
  • Cyber Security
  • Data Privacy
  • How To
  • Latest
  • linux
  • News
  • Technology
  • Web Security

Tags

2FA (1) API (1) Artificial Intelligence (1) audit (1) Cyber Security (1) data privacy (1) github (1) github account (1) Linux (1) Network (1) Network Security (1) privacy (1) Security (2) Security Guide (1) Web Security (1) web security audit (1) website security (1) Wifi (1)

Explore More

  • About Us
  • Advertise
  • Contact Us
  • Guides
  • Home
  • News
  • Privacy
  • Privacy Policy
  • Resources
  • Reviews
  • Security
  • Tech
  • Tools
    • Strong Password Generator

Stay Connected

© 2023 -2024 SecurityGuide.net - Cyber Security News Today - Latest News and Updates About Security SecurityGuide.net.

No Result
View All Result
  • About Us
  • Advertise
  • Contact Us
  • Guides
  • Home
  • News
  • Privacy
  • Privacy Policy
  • Resources
  • Reviews
  • Security
  • Tech
  • Tools
    • Strong Password Generator

© 2023 -2024 SecurityGuide.net - Cyber Security News Today - Latest News and Updates About Security SecurityGuide.net.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In