Collected every two hours from specialised publications — each link leads to the original article.
It was discovered that OpenSSH incorrectly handled loading certain PKCS#11 providers. If a user forwarded their ssh-agent to an untrusted system, a remote atta…
A hardening measure was added to OpenSSH.
Two critical remote code execution (RCE) vulnerabilities have been found in OpenSSH (CVE-2023-28531 and CVE-2023-38408). Because these bugs are simple to explo…
openssh: Remote code execution in ssh-agent PKCS#11 support (CVE-2023-38408) For more details about the security issue(s), including the impact, a CVSS score, …
An update for openssh is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a se…
An update for openssh is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a sec…
An update for openssh is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important.…
OpenSSH could be made to run programs as your login when using ssh-agent forwarding.
An update for openssh is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a sec…
OpenSSH could be made to run programs as your login when using ssh-agent forwarding.
Details have emerged about a now-patched flaw in OpenSSH that could be potentially exploited to run arbitrary commands remotely on compromised hosts under spec…
Multiple vulnerbilities have been discovered in OpenSSH, the worst of which could result in remote code execution.
New openssh packages are available for Slackware 15.0 and -current to fix a security issue.
An update for openssh is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. …
New openssh packages are available for Slackware 15.0 and -current to fix security issues.
The maintainers of OpenSSH have released OpenSSH 9.2 to address a number of security bugs, including a memory safety vulnerability in the OpenSSH server (sshd)…
New openssh packages are available for Slackware 15.0 and -current to fix security issues.
OpenSSH could be made to run arbitrary code if it some non-default configuration are in use.
openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured (CVE-2021-41617) For more details about the security iss…
An update for openssh is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. …
USN-3809-1 introduced a regression in OpenSSH.
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy op…
Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to execute arbitrary code.
OpenSSH ' secure protocol to connect and manage remote servers ' has announced dropping support for SHA-1 logins. The serviceOpenSSH Drops Support For SHA-1 Lo…