MidnightBSD / src

MidnightBSD OS source code
https://www.midnightbsd.org/
Other
55 stars 6 forks source link

CVE-2024-6387 (High) detected in multiple libraries #216

Closed mend-bolt-for-github[bot] closed 4 months ago

mend-bolt-for-github[bot] commented 4 months ago

CVE-2024-6387 - High Severity Vulnerability

Vulnerable Libraries - src3.1.5, src3.1.5, src3.1.5, src3.1.5, src3.1.5, src3.1.5

Vulnerability Details

A critical vulnerability in sshd(8) was present in Portable OpenSSH versions between 8.5p1 and 9.7p1 (inclusive) that may allow arbitrary code execution with root privileges.

Publish Date: 2024-06-27

URL: CVE-2024-6387

CVSS 3 Score Details (8.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: High - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.openssh.com/txt/release-9.8

Release Date: 2024-06-27

Fix Resolution: V_9_8_P1


Step up your Open Source Security Game with Mend here

laffer1 commented 4 months ago

Fix merged