Release of OpenSSH 9.6 with vulnerability fixes

The release of OpenSSH 9.6 has been published, an open-source implementation of the client and server for SSH 2.0 and SFTP protocols. This new version addresses three security issues:

  • A vulnerability in the SSH protocol (CVE-2023-48795, the 'Terrapin' attack) that allows a downgrade of the connection to less secure authentication algorithms during a MITM attack and disables the protection against attacks that exploit the timing of key presses on the keyboard. The method of attack is detailed in a separate news article.
  • A vulnerability in the ssh utility that allows arbitrary shell command substitution through manipulation of login and host values containing special characters. The vulnerability can be exploited if the attacker controls the login and hostname values passed to ssh, the ProxyCommand and LocalCommand directives, or the match exec blocks that specify substitution characters like %u and %h. For example, incorrect login and host values can be substituted in systems using Git submodules, as Git does not prohibit special characters in the hostname and username. A similar vulnerability is also present in libssh.
  • An error in ssh-agent, which caused restrictions to apply only to the first key returned by the PKCS#11 token when adding private keys. This issue does not affect regular private keys, FIDO tokens, or keys specified without restrictions.

Other changes:

  • The ssh utility has added substitution '%j', which expands to the hostname specified via the ProxyJump directive.
  • Support has been added in ssh for configuring ChannelTimeout on the client side, which can be used to terminate inactive channels.
  • Support for reading ED25519 private keys in PEM PKCS8 format has been added to ssh, sshd, ssh-add, and ssh-keygen (previously, only OpenSSH format was supported).
  • A protocol extension has been added to ssh and sshd for renegotiating digital signature algorithms for public key authentication, which takes place after receiving the username information. For example, this extension allows selective use of different algorithms tied to users by specifying PubkeyAcceptedAlgorithms in the 'Match user' block.
  • In ssh-add and ssh-agent, a protocol extension has been added for specifying certificates when loading PKCS#11 keys, enabling the use of certificates associated with PKCS#11 private keys in all OpenSSH utilities that support ssh-agent, not just in ssh.
  • Improved detection of unsupported or unstable compiler flags, such as '-fzero-call-used-regs' in clang.
  • To limit the privileges of the sshd process in OpenSolaris versions supporting the getpflags() interface, the PRIV_XPOLICY mode has been engaged instead of PRIV_LIMIT.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster