UBUNTU-CVE-2023-51385
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-51385
UBUNTU-CVE-2023-51385
Summary:
Details: In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
References: https://ubuntu.com/security/CVE-2023-51385, https://www.openwall.com/lists/oss-security/2023/12/18/2, https://www.openssh.com/txt/release-9.6, https://ubuntu.com/security/notices/USN-6565-1, https://ubuntu.com/security/notices/USN-6560-2, https://www.cve.org/CVERecord?id=CVE-2023-51385, https://ubuntu.com/security/notices/USN-6560-3
Affected packages
Package
Name: openssh
Purl: pkg:deb/ubuntu/openssh?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
