CVE-2024-6387 in Virtual Appliance
search cancel

CVE-2024-6387 in Virtual Appliance

book

Article ID: 386856

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

 The security scan detected the following security risk: OpenSSH Vulnerability: CVE-2024-6387, CVSS score = 7.6, CVSSv3 score = 8.1. A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner.

An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Environment

14.5.X Virtual Appliance

Resolution

Please make sure to install Latest Operating System Security Patch which contains openssh version 8.7p1 which was backported with fixes for regreSSHion issue - CVE-2024-6387.