From 5fe3672f0ef7f8811b3da31d99c01624cb481358 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adrian=20Schr=C3=B6ter?= Date: Wed, 17 Jul 2024 15:00:44 +0200 Subject: [PATCH] Adding patchinfo patchinfo.20240704202834160238.269002615871826 --- .../_patchinfo | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 patchinfo.20240704202834160238.269002615871826/_patchinfo diff --git a/patchinfo.20240704202834160238.269002615871826/_patchinfo b/patchinfo.20240704202834160238.269002615871826/_patchinfo new file mode 100644 index 0000000..f512327 --- /dev/null +++ b/patchinfo.20240704202834160238.269002615871826/_patchinfo @@ -0,0 +1,23 @@ + + + VUL-0: CVE-2023-48795: openssh: prefix truncation breaking ssh channel integrity aka Terrapin Attack + VUL-0: CVE-2023-51385: openssh: command injection via user name or host name metacharacters + VUL-0: CVE-2024-6387: openssh: regression of CVE-2006-5051 + + + + VUL-0: CVE-2024-39894: openssh: timing attacks against echo-off password entry + + alarrosa + critical + security + Security update for openssh + This update for openssh fixes the following issues: + +- CVE-2024-39894: Fixed timing attacks against echo-off password entry (bsc#1227318) +- CVE-2024-6387: Fixed race condition in a signal handler (bsc#1226642). + + openssh + openssh:openssh-askpass-gnome + +