“RegreSSHion” vulnerability in OpenSSH gives attackers root on Linux
image via Ars Technica
July 2, 2024, 7:03 PM
- •A critical vulnerability affecting the OpenSSH networking utility could be exploited to give attackers complete control of Linux and Unix servers with no authentication required.
- •The vulnerability, tracked as CVE-2024-6387, allows unauthenticated remote code execution with root system rights on Linux systems that are based on glibc, an open source implementation of the C standard library.
- •The risk is in part driven by the central role OpenSSH plays in virtually every internal network connected to the Internet. It provides a channel for administrators to connect to protected devices remotely or from one device to another inside the network.
Researchers have warned of a critical vulnerability affecting the OpenSSH networking utility that can be exploited to give attackers complete control of Linux and Unix servers with no authentication required. The vulnerability, tracked as CVE-2024-6387, allows unauthenticated remote code execution with root system rights on Linux systems that are based on glibc, an open source implementation of the C standard library. With thousands, if not millions, of vulnerable servers populating the Internet, this latest vulnerability could pose a significant risk.
Entities Mentioned
Bharat JogiStan Kaminsky
Topics Covered
Biz & ITSecuritycode executionexploitsopensshvulnerabilities
Comments (0)
No comments yet.