Advisories ยป MGASA-2021-0561

Updated openssh packages fix security vulnerability

Publication date: 19 Dec 2021
Modification date: 19 Dec 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-41617

Description

Updated openssh packages fix security vulnerability:

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default
configurations are used, allows privilege escalation because supplemental
groups are not initialized as expected. Helper programs for
AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with
privileges associated with group memberships of the sshd process, if the
configuration specifies running the command as a different user
(CVE-2021-41617).
                

References

SRPMS

8/core