Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Issue] hpn-ssh seems be to vulnerable to a critical threat CVE-2024-6387 #87

Closed
IceCodeNew opened this issue Jul 1, 2024 · 7 comments

Comments

@IceCodeNew
Copy link

The latest release of the hpn-ssh was based on OpenSSH 9.7, which is vulnerable to the regression of CVE-2006-5051, according to the report

Thought it is worth raising concern about that problem, I wish I did not intervene in the normal process of development.

@IceCodeNew IceCodeNew changed the title hpn-ssh seems be to vulnerable to a critical threat CVE-2024-6387 [Security Issue] hpn-ssh seems be to vulnerable to a critical threat CVE-2024-6387 Jul 1, 2024
@rapier1
Copy link
Owner

rapier1 commented Jul 1, 2024

We've just been made aware of this but we already had started work on porting to 9.8. I hope to have a release ready by the end of the day but that may slip until tomorrow.

@IceCodeNew
Copy link
Author

Glad to hear about it. I should not bother to ask ;=)
Appreciate the quick response 👍👍👍

@rapier1
Copy link
Owner

rapier1 commented Jul 2, 2024

We've had to change plans and we have backported the fix from 9.8 to the 9.7 code base. This is available in master with the tag hpn-18.4.2.

The 9.8 port is taking longer than expected - especially with the packages. We thought this was the best move forward at this time. We will get to 9.8 as soon as we can but the US holiday will delay things.

@IceCodeNew
Copy link
Author

IceCodeNew commented Jul 3, 2024

The debian packages seems missed the release. Would you mind to take a look at it?

@rapier1
Copy link
Owner

rapier1 commented Jul 3, 2024

I didn't have a chance to get to those yesterday. I will be getting those in place in about an hour. My apologies for the delay.

@rapier1
Copy link
Owner

rapier1 commented Jul 3, 2024

Debian packages should now be available from https://download.opensuse.org/repositories/home:/rapier1

Functional Ubuntu packages should also be available from the launchpad PPA.

@IceCodeNew
Copy link
Author

IceCodeNew commented Jul 3, 2024

The patched version is confirmed been available on Debian 12, rocky Linux 9.4, Fedora 40, & Ubuntu 22.04 ;-)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants