RegreSSHion: Remote Code Execution Vulnerability In OpenSSH Server
([Linux Security] 4 Hours Ago
CVE-2024-6387)
- Reference: 0001474707
- News link: https://www.phoronix.com/news/RegreSSHion-CVE-2024-6387
- Source link:
Qualys went public today with a security vulnerability they have discovered within the OpenSSH server that could lead to remote, unauthenticated code execution.
OpenSSH servers running with the GNU C Library (glibc) in Linux environments are vulnerable to CVE-2024-6387, or the vulnerability they have dubbed "RegreSSHion" as a play on "SSH" and "regression".
A signal handler race condition within the OpenSSH server could lead to unauthenticated remote code execution. Various versions of OpenSSH going back years are affected on Linux.
Qualys noted in their research:
"This vulnerability, if exploited, could lead to full system compromise where an attacker can execute arbitrary code with the highest privileges, resulting in a complete system takeover, installation of malware, data manipulation, and the creation of backdoors for persistent access. It could facilitate network propagation, allowing attackers to use a compromised system as a foothold to traverse and exploit other vulnerable systems within the organization."
More details on CVE-2024-6387 as this severe OpenSSH security vulnerability for Linux servers can be found via the [1]Qualys blog .
[1] https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server
OpenSSH servers running with the GNU C Library (glibc) in Linux environments are vulnerable to CVE-2024-6387, or the vulnerability they have dubbed "RegreSSHion" as a play on "SSH" and "regression".
A signal handler race condition within the OpenSSH server could lead to unauthenticated remote code execution. Various versions of OpenSSH going back years are affected on Linux.
Qualys noted in their research:
"This vulnerability, if exploited, could lead to full system compromise where an attacker can execute arbitrary code with the highest privileges, resulting in a complete system takeover, installation of malware, data manipulation, and the creation of backdoors for persistent access. It could facilitate network propagation, allowing attackers to use a compromised system as a foothold to traverse and exploit other vulnerable systems within the organization."
More details on CVE-2024-6387 as this severe OpenSSH security vulnerability for Linux servers can be found via the [1]Qualys blog .
[1] https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server
clavko