Re: Security vulnerability— action required :please update openssh in you project of releng/14.0 to 9.6p1 like branch master

Gordon Tetlow <[email protected]> Wed, 4 Sep 2024 21:27:06 -0700
Newsgroups gmane.os.freebsd.security.general
Message-ID <[email protected]>
> On Sep 4, 2024, at 7:26 PM, James Watt <[email protected]> wrote:
> 
> Hi,
>   we have detected that your project of release/14.0 is vulnerable to the  CVE-2023-51384 which is caused by the lower version of openssh, maybe you need to update it?
> 
> Best regards,
> James
> 

Hi James,

We (secteam) try to avoid wholesale upgrade of OpenSSH in our release branches. As such, we take a risk-based approach on what we pull into the tree. Given this particular CVE is related to ssh-agent with a specific set of circumstances (multiple PKCS#11 keys with destination constraints), we opted not to publish an update for it. Users who want to defend from this particular CVE could either use the OpenSSH from ports/pkg or directly upgrade to 14.1-RELEASE.

Lastly, given that 14.0-RELEASE is going out of support at the end of this month, this will be overcome by events pretty shortly.

On an unrelated note, your note says that “we” have detected the old version. Out of curiosity, do you represent a broader organization? Your email address being hosted on gmail.com <http://gmail.com/> makes it difficult to know.

Thanks,
Gordon
Hat: security-officer
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEuyjUCzYO7pNq7RVv5fe8y6O93fgFAmbZMxoACgkQ5fe8y6O9
3fjhggf/VMLfW1OiUznWHaDcTCkFiVn/1Xb8K1Dct1O8RQR+9V/keTzLV6/eR78y
+0MfI4PXflPttNxRykqbN+RBXgdjyNfrZaJNTDRq+QhzjtoQAeoOXDZfnc6wI45I
V+0jUDu69M2FBOQ377loG7gWotrOL3uKNmNyqEnG5qx7lEH/Sm1t8+fO5DVCD2wH
U6Jl7baQeX5ESiuq+t3flEohwfdgDrZoJJds3D8wmRAToyF+cBgUSNpN1qfeSekv
6yJjH6DcQlO8y3WNLMuSyl4052ohNts5u/cxJIet8WZ8vaw/+sfxXzf6FpYudl+4
wH3hgPz7mFwtXl3UDRIitLs1Q1ksZA==
=ofLF
-----END PGP SIGNATURE-----