[DSA 5868-1] openssh security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5868-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
February 18, 2025                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : openssh
CVE ID         : CVE-2025-26465

The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client
is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS
option is enabled (disabled by default).

Details can be found in the Qualys advisory at
https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt

For the stable distribution (bookworm), this problem has been fixed in
version 1:9.2p1-2+deb12u5.

We recommend that you upgrade your openssh packages.

For the detailed security status of openssh please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/openssh

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAme0UcFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0R+fQ/+KSOsO+Q6AElkn2PdD33iSn4fMqDHWSANy6Q8wNL10KtTlPMoi5NVusky
G17RxxU3t9VmoxS0dq7iHLmVjDqXJ+R1cLjvMlnrkdm7qAteg7o17GMjyXhJ9F7w
zJOy9hC6RKngUiYvQbbHdn+m47QNGfOQeCO1AmrWHduySCtNcnAHnQJUDH/Xp57R
RaQiM2dWHLjUs7jQxMx9uI5lw9Y1LqL17IQeErBn5LkrKqCZbU/JHtJbUsea+HLN
kWNue8SgWlnXBRwDSHJGEp+J+u8cavUAHmSyTB1dJ6b2/EdMyjwOaJO2VvT7S9UF
UktU3xqPRJMHrQ3a/wCmqU4QbLcwddU0LulNYPysbQJI0R3iz24KFPRKSsX8FXGC
lSxgHAHqAfxQT55FgkGbeL9i69qEYH8eEp2KsdfuEd3WaEfKbTRkV+VyQxI48nqs
39OiytBcZO+F+m4QzOlg/mngqkSjqV4OLqNN28JTsLUjeIedy6gcM5GCIG3ibkIn
0R0YXoxBFIyvKFujyV6kAxJmrC1cS0ucSkJvHqY+rE21OAlKqMyPVr4SNOvD2W7k
n8J1cIcqWcibWGkoTIMQ7VtF8YgXWoL/D+T8861qKBAdXaR8havnxWlDnox/27Bg
9BvStkAiFTztkMTgzDyGS35cCaSPhIZgPHOCB07Mpf5WkXEpJh4=
=uuLi
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.