The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssh | Aug 30, 2017 | Nov 8, 2013 |
| Debian | — | Upgrade openssh | Jul 30, 2024 | Nov 8, 2013 |
| Hpux | — | Update Secure_Shell.SECURE_SHELL to the latest versionUpdate Secure_Shell.SECSH-CMN to the latest version | Aug 11, 2017 | Nov 8, 2013 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory3 | Nov 30, 2017 | Nov 8, 2013 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 6.4 | Nov 15, 2013 | Nov 8, 2013 |
| Suse | — | Upgrade opensshUpgrade openssh-askpass-gnome | Feb 17, 2015 | Nov 8, 2013 |
| Ubuntu | — | Upgrade openssh-server | Nov 8, 2024 | Nov 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub