[ELSA-2024-12233] openssh security update

Severity Moderate
Affected Packages 9
CVEs 1

[7.4p1-23.0.3_fips]
- Change Epoch from 1 to 10
- Enable fips KDF POST [Orabug: 32461750]
- Disable diffie-hellman-group-exchange-sha256 KEX FIPS method [Orabug: 32461739]

[7.4p1-23.0.3]
- add KEX_INITIAL flag [Orabug: 36160445]
- implement 'strict key exchange' [CVE-2023-48795][Orabug: 36160445]

ID
ELSA-2024-12233
Severity
moderate
URL
https://linux.oracle.com/errata/ELSA-2024-12233.html
Published
2024-03-18T00:00:00
(6 months ago)
Modified
2024-03-18T00:00:00
(6 months ago)
Rights
Copyright 2024 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/pam_ssh_agent_auth?distro=oraclelinux-7.9 oraclelinux pam_ssh_agent_auth < 0.10.3-2.23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh?distro=oraclelinux-7.9 oraclelinux openssh < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh-server?distro=oraclelinux-7.9 oraclelinux openssh-server < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh-server-sysvinit?distro=oraclelinux-7.9 oraclelinux openssh-server-sysvinit < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh-ldap?distro=oraclelinux-7.9 oraclelinux openssh-ldap < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh-keycat?distro=oraclelinux-7.9 oraclelinux openssh-keycat < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh-clients?distro=oraclelinux-7.9 oraclelinux openssh-clients < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh-cavs?distro=oraclelinux-7.9 oraclelinux openssh-cavs < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssh-askpass?distro=oraclelinux-7.9 oraclelinux openssh-askpass < 7.4p1-23.0.3.el7_9_fips oraclelinux-7.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...