CVE-2023-6004

Published: December 19, 2023Last modified: December 19, 2023

Description

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.

Severity score breakdown

ParameterValue
Base score4.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsshFixed (0.10.6-r0)
StreamlibsshFixed (0.10.6-r0)

References

Published BELL-SAs

ON THIS PAGE