Crypto Ticker:
sysadmin from Cyber Security News

Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks

Guru Baran
8 hours ago
14 Views
0 Comments
Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks

OpenSSH 10.6, released on October 6, 2026, fixes security flaws that could expose secrets, write files outside intended folders, or enable shell injection under specific conditions. The update covers both client and server tools, making it relevant to administrators and users who rely on SSH for remote access and file transfers. The official release notes describe separate weaknesses with different attack requirements, not a single attack affecting every installation. The main concerns involve shared compression across SSH channels, paths returned by SFTP servers, and untrusted usernames passed to shell commands. SSH Plaintext Recovery Risk Researchers Fabian Bäumer and Marcus Brinkmann describe the compression flaw in Crossing...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!