[ALAS2-2023-2376] Amazon Linux 2 2017.12 - ALAS2-2023-2376: medium priority package update for openssh

Severity Medium
Affected Packages 30
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2023-48795:
Placeholder CVE. Details forthcoming

Package Affected Version
pkg:rpm/amazonlinux/pam_ssh_agent_auth?arch=x86_64&distro=amazonlinux-2 < 0.10.3-2.22.amzn2.0.6
pkg:rpm/amazonlinux/pam_ssh_agent_auth?arch=i686&distro=amazonlinux-2 < 0.10.3-2.22.amzn2.0.6
pkg:rpm/amazonlinux/pam_ssh_agent_auth?arch=aarch64&distro=amazonlinux-2 < 0.10.3-2.22.amzn2.0.6
pkg:rpm/amazonlinux/openssh?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-server?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-server?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-server?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-server-sysvinit?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-server-sysvinit?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-server-sysvinit?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-ldap?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-ldap?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-ldap?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-keycat?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-keycat?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-keycat?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-debuginfo?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-debuginfo?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-debuginfo?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-clients?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-clients?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-clients?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-cavs?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-cavs?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-cavs?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-askpass?arch=x86_64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-askpass?arch=i686&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
pkg:rpm/amazonlinux/openssh-askpass?arch=aarch64&distro=amazonlinux-2 < 7.4p1-22.amzn2.0.6
ID
ALAS2-2023-2376
Severity
medium
URL
https://alas.aws.amazon.com/AL2/ALAS-2023-2376.html
Published
2023-12-14T22:44:00
(9 months ago)
Modified
2023-12-14T22:44:00
(9 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/pam_ssh_agent_auth?arch=x86_64&distro=amazonlinux-2 amazonlinux pam_ssh_agent_auth < 0.10.3-2.22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/pam_ssh_agent_auth?arch=i686&distro=amazonlinux-2 amazonlinux pam_ssh_agent_auth < 0.10.3-2.22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/pam_ssh_agent_auth?arch=aarch64&distro=amazonlinux-2 amazonlinux pam_ssh_agent_auth < 0.10.3-2.22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh?arch=i686&distro=amazonlinux-2 amazonlinux openssh < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-server?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-server < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-server?arch=i686&distro=amazonlinux-2 amazonlinux openssh-server < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-server?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-server < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-server-sysvinit?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-server-sysvinit < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-server-sysvinit?arch=i686&distro=amazonlinux-2 amazonlinux openssh-server-sysvinit < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-server-sysvinit?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-server-sysvinit < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-ldap?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-ldap < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-ldap?arch=i686&distro=amazonlinux-2 amazonlinux openssh-ldap < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-ldap?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-ldap < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-keycat?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-keycat < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-keycat?arch=i686&distro=amazonlinux-2 amazonlinux openssh-keycat < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-keycat?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-keycat < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-debuginfo < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux openssh-debuginfo < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-debuginfo < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-clients?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-clients < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-clients?arch=i686&distro=amazonlinux-2 amazonlinux openssh-clients < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-clients?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-clients < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-cavs?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-cavs < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-cavs?arch=i686&distro=amazonlinux-2 amazonlinux openssh-cavs < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-cavs?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-cavs < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssh-askpass?arch=x86_64&distro=amazonlinux-2 amazonlinux openssh-askpass < 7.4p1-22.amzn2.0.6 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssh-askpass?arch=i686&distro=amazonlinux-2 amazonlinux openssh-askpass < 7.4p1-22.amzn2.0.6 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssh-askpass?arch=aarch64&distro=amazonlinux-2 amazonlinux openssh-askpass < 7.4p1-22.amzn2.0.6 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...