Name | CVE-2023-51385 |
Description | In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3694-1, DSA-5586-1, ELA-1038-1, ELA-1055-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
openssh (PTS) | jessie, jessie (lts) | 1:6.7p1-5+deb8u10 | fixed |
stretch (security) | 1:7.4p1-10+deb9u6 | vulnerable | |
stretch (lts), stretch | 1:7.4p1-10+deb9u9 | fixed | |
buster (security), buster, buster (lts) | 1:7.9p1-10+deb10u4 | fixed | |
bullseye (security), bullseye | 1:8.4p1-5+deb11u3 | fixed | |
bookworm (security), bookworm | 1:9.2p1-2+deb12u3 | fixed | |
sid, trixie | 1:9.9p1-3 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
openssh | source | jessie | 1:6.7p1-5+deb8u10 | ELA-1055-1 | ||
openssh | source | stretch | 1:7.4p1-10+deb9u9 | ELA-1038-1 | ||
openssh | source | buster | 1:7.9p1-10+deb10u4 | DLA-3694-1 | ||
openssh | source | bullseye | 1:8.4p1-5+deb11u3 | DSA-5586-1 | ||
openssh | source | bookworm | 1:9.2p1-2+deb12u2 | DSA-5586-1 | ||
openssh | source | (unstable) | 1:9.6p1-1 |
https://www.openwall.com/lists/oss-security/2023/12/18/2
https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a (V_9_6_P1)
https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html