Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://nvd.nist.gov/vuln/detail/CVE-2023-25136

> OpenSSH server (sshd) 9.1 introduced

https://security-tracker.debian.org/tracker/CVE-2023-25136

Is this even exploitable in any distributed configuration, considering that it requires enabling old deprecated key exchange algorithms?



This is exploitable in the latest Archlinux 2023.02.01. Also, this doesn't require enabling old key exchange algorithms.


What does "the latest Arch Linux" mean? Arch Linux is a rolling distribution. It was patched in the repository on 2023-02-02[0].

[0] https://archlinux.org/packages/core/x86_64/openssh/


I assume they mean the latest version available for download as an .iso, since I think that tends to happen around monthly. I agree that this isn't super concerning though, since even installing from that would result in an up-to-date system, and there isn't much reason to ssh to or from the live disk.


Needed fixing regardless and is fixed in 9.2.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: