Bug 7796 - [Anolis OS 23] Bugfix for CVE-2023-6004
Summary: [Anolis OS 23] Bugfix for CVE-2023-6004
Status: RESOLVED FIXED
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P4-Low S4-trivial
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-12-25 14:47 UTC by 小龙
Modified: 2023-12-25 14:48 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-12-25 14:47:29 UTC
Description:
Using the ProxyCommand or the ProxyJump feature enables users to exploit
unchecked hostname syntax on the client, which enables to inject malicious code
into the command of the above-mentioned features through the hostname parameter.

User interaction is required to exploit this issue.

Broken commit info:

Bugfix commit info:
https://git.libssh.org/projects/libssh.git/commit/?id=2c92e8ce930a428a6fd150ae1ae55c5a365543f5
https://gitlab.com/libssh/libssh-security/-/merge_requests/26
https://git.libssh.org/projects/libssh.git/commit/?id=95c6f880ef1539635bb82a134f7b8a06a46887ca
https://git.libssh.org/projects/libssh.git/commit/?id=0ff85b034a04d45e79a79cd5666b348b5e27800d
Comment 1 小龙 admin 2023-12-25 14:48:03 UTC
PR: 
https://gitee.com/src-anolis-os/libssh/pulls/16