UBUNTU-CVE-2023-51385
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
02 / AFFECTED SOFTWARE
Affected packages
4 explicit affected versions
13 explicit affected versions
1 explicit affected versions
10 explicit affected versions
3 explicit affected versions
2 explicit affected versions
4 explicit affected versions
1 explicit affected versions
2 explicit affected versions
25 explicit affected versions
27 explicit affected versions
10 explicit affected versions
8 explicit affected versions
7 explicit affected versions
3 explicit affected versions
9 explicit affected versions
2 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2023-51385
- https://ubuntu.com/security/notices/USN-6560-2
- https://ubuntu.com/security/notices/USN-6560-3
- https://ubuntu.com/security/notices/USN-6565-1
- https://www.cve.org/CVERecord?id=CVE-2023-51385
- https://www.openssh.com/txt/release-9.6
- https://www.openwall.com/lists/oss-security/2023/12/18/2