OS Command Injection In openssh
Description
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1:8.4p1-5+deb11u7 | ||
debian 12 | 1:9.2p1-2+deb12u8 | ||
debian 13 | 1:10.0p1-7+deb13u1 | ||
debian 14 | 1:10.1p1-1 | ||
alpine v3.22 | 10.0_p1-r10 | ||
alpine v3.23 | 10.1_p1-r0 | ||
rpm rhel10 | 0:9.9p1-12.el10_1 | ||
rpm rhel10.0 | 0:9.9p1-7.el10_0.1 | ||
rpm rhel8 | 0:8.0p1-27.el8_10 | ||
rpm rhel9 | 0:8.7p1-47.el9_7 |
1-10 of 15
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1.