VDB

ALSA-2024%3A3233

ALSA-2024%3A3233 PUBLISHED

libssh is a library which implements the SSH protocol. It can be used to implement client and server applications. Security Fix(es): * libssh: ProxyCommand/ProxyJump features allow injection of malicious code through hostname (CVE-2023-6004) * libssh: Missing checks for return values for digests (CVE-2023-6918) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Affected Products

VendorProductVersions
AlmaLinux:8libssh0, 0
AlmaLinux:8libssh-devel0, 0
AlmaLinux:8libssh-config0, 0

Timeline

  • May 22, 2024 CVE Published
  • May 29, 2024 CVE Updated
  • Mar 6, 2026 Distribution Patch
  • Mar 6, 2026 Distribution Patch
  • Mar 6, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›