Kryptovalutaticker:
sysadmin från Cyber Security News

Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks

Guru Baran
8 hours ago
15 Visningar
0 Kommentarer
Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks

OpenSSH 10.6, released on October 6, 2026, fixes security flaws that could expose secrets, write files outside intended folders, or enable shell injection under specific conditions. The update covers both client and server tools, making it relevant to administrators and users who rely on SSH for remote access and file transfers. The official release notes describe separate weaknesses with different attack requirements, not a single attack affecting every installation. The main concerns involve shared compression across SSH channels, paths returned by SFTP servers, and untrusted usernames passed to shell commands. SSH Plaintext Recovery Risk Researchers Fabian Bäumer and Marcus Brinkmann describe the compression flaw in Crossing...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!