Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname
Published Jan 3, 2024
4.8
MEDIUMCVSS 3.1
EPSS 0.45%
Description
A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.
Affected products
No data.
Configuration 1
Configuration 2
- 38
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
libssh-0:0.9.6-14.el8
Fixed · RHSA-2024:3233
Red Hat Enterprise Linux 8
libssh-0:0.9.6-14.el8
Fixed · RHSA-2024:3233
Red Hat Enterprise Linux 9
libssh-0:0.10.4-13.el9
Fixed · RHSA-2024:2504
Red Hat Enterprise Linux 9
libssh-0:0.10.4-13.el9
Fixed · RHSA-2024:2504
Red Hat Enterprise Linux 7
libssh
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libssh-0:0.9.6-14.el8 | Fixed | RHSA-2024:3233 |
| Red Hat Enterprise Linux 8 | libssh-0:0.9.6-14.el8 | Fixed | RHSA-2024:3233 |
| Red Hat Enterprise Linux 9 | libssh-0:0.10.4-13.el9 | Fixed | RHSA-2024:2504 |
| Red Hat Enterprise Linux 9 | libssh-0:0.10.4-13.el9 | Fixed | RHSA-2024:2504 |
| Red Hat Enterprise Linux 7 | libssh | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Despite the potential severity of this issue, the requirement for user interaction to exploit the vulnerability has led to a low severity rating. As a precautionary measure, users are advised to sanitize hostname inputs as a mitigation strategy.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/errata/RHSA-2024:2504 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:3233 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6004 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2251110 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58271 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/
- https://nvd.nist.gov/vuln/detail/CVE-2023-6004
- https://security.netapp.com/advisory/ntap-20240223-0004/
- https://www.cve.org/CVERecord?id=CVE-2023-6004
- https://www.libssh.org/security/advisories/CVE-2023-6004.txt Mailing List
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:2504 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:3233 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2023-6004 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2251110 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58271 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/ | ||
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-6004 | ||
| https://security.netapp.com/advisory/ntap-20240223-0004/ | ||
| https://www.cve.org/CVERecord?id=CVE-2023-6004 | ||
| https://www.libssh.org/security/advisories/CVE-2023-6004.txt | Mailing List |
Change history (0)
No recorded changes yet.