OpenSSH 爆高危漏洞 CVE-2024-6387

4 天前
 frencis107
影响版本号 8.5p1 ~ 9.7p1......
https://www.reddit.com/r/msp/comments/1dsse9e/security_awareness_openssh_cve20246387_rce/

https://security-tracker.debian.org/tracker/CVE-2024-6387
https://ubuntu.com/security/CVE-2024-6387


今年下半年才刚开始
16295 次点击
所在节点    信息安全
131 条回复
cnt2ex
4 天前
自从 xz 事件之后,我已经把监听地址限制在一个 VPN 的地址上了
darksheen
4 天前
看了下我的 almalinux 8 ,用的还是 8.0p1 呢
LingXingYue
4 天前
ubuntu 的软件源好像还没更新,可以自己手动编译安装,也很快
# 安装编译依赖
sudo apt-get update
sudo apt-get install -y build-essential zlib1g-dev libssl-dev

# 下载指定版本源码
wget https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-9.8p1.tar.gz

# 解压并进入目录
tar -xzf openssh-9.8p1.tar.gz
cd openssh-9.8p1

# 编译和安装
./configure
make
sudo make install

# 启动并检查安装
sudo systemctl restart ssh
ssh -V
cat
4 天前
@LingXingYue 不自己编译的话 是不是只能等 apt 更新啊
chenluo0429
4 天前
睡前看到,顺手更新了
AstroProfundis
4 天前
别瞎搞,sudo make install 完就再也不用包管理更新了呗?
LeviMarvin
4 天前
ArchLinux 躺赢。OpenSSH_9.8p1, OpenSSL 3.3.1 4 Jun 2024
huagequan
4 天前
https://ubuntu.com/security/notices/USN-6859-1
Ubuntu 的软件源好像更新了
yukino
4 天前
@LeviMarvin openssh 最新版 9.8p1-1 ,该 `pacman -Syu` 了
FanChou
4 天前
cat
4 天前
@huagequan apt update 还是没有,要怎么更新这个啊,求教
huagequan
4 天前
@cat 你是什么版本的 Ubuntu
yyzh
4 天前
@LingXingYue ubuntu 出紧急更新了
StinkyTofus
4 天前
我擦,赶紧升级呀
choury
4 天前
@cat 源里已经修了,要么你没加 security 仓库,要么你用的 mirror 同步有延迟
```
sudo apt upgrade
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Calculating upgrade... Done
The following packages will be upgraded:
openssh-client openssh-server openssh-sftp-server ssh
4 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Need to get 1,687 kB of archives.
After this operation, 0 B of additional disk space will be used.
Do you want to continue? [Y/n] y
Get:1 http://deb.debian.org/debian-security bookworm-security/main amd64 openssh-sftp-server amd64 1:9.2p1-2+deb12u3 [65.8 kB]
Get:2 http://deb.debian.org/debian-security bookworm-security/main amd64 openssh-server amd64 1:9.2p1-2+deb12u3 [456 kB]
Get:3 http://deb.debian.org/debian-security bookworm-security/main amd64 openssh-client amd64 1:9.2p1-2+deb12u3 [991 kB]
Get:4 http://deb.debian.org/debian-security bookworm-security/main amd64 ssh all 1:9.2p1-2+deb12u3 [174 kB]
Fetched 1,687 kB in 2min 20s (12.0 kB/s)
Reading changelogs... Done
Preconfiguring packages ...
(Reading database ... 94393 files and directories currently installed.)
Preparing to unpack .../openssh-sftp-server_1%3a9.2p1-2+deb12u3_amd64.deb ...
Unpacking openssh-sftp-server (1:9.2p1-2+deb12u3) over (1:9.2p1-2+deb12u2) ...
Preparing to unpack .../openssh-server_1%3a9.2p1-2+deb12u3_amd64.deb ...
Unpacking openssh-server (1:9.2p1-2+deb12u3) over (1:9.2p1-2+deb12u2) ...
Preparing to unpack .../openssh-client_1%3a9.2p1-2+deb12u3_amd64.deb ...
Unpacking openssh-client (1:9.2p1-2+deb12u3) over (1:9.2p1-2+deb12u2) ...
Preparing to unpack .../ssh_1%3a9.2p1-2+deb12u3_all.deb ...
Unpacking ssh (1:9.2p1-2+deb12u3) over (1:9.2p1-2+deb12u2) ...
Setting up openssh-client (1:9.2p1-2+deb12u3) ...
Setting up openssh-sftp-server (1:9.2p1-2+deb12u3) ...
Setting up openssh-server (1:9.2p1-2+deb12u3) ...

```
StinkyTofus
4 天前
Centos7.9 目前还是 OpenSSH_7.4p1 版本, 是不是无敌了。不用升级了?
cat
4 天前
@choury @huagequan Ubuntu 22.04 的,已经把 source.list 切换成官方的了,依然没有……

sudo apt upgrade
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Calculating upgrade... Done
Get more security updates through Ubuntu Pro with 'esm-apps' enabled:
gsasl-common libgsasl7
Learn more about Ubuntu Pro at https://ubuntu.com/pro
The following packages have been kept back:
cloud-init python3-update-manager ubuntu-advantage-tools ubuntu-pro-client ubuntu-pro-client-l10n
update-manager-core
0 upgraded, 0 newly installed, 0 to remove and 6 not upgraded.
huagequan
4 天前
@cat apt policy openssh-server 这个命令看看版本
cat
4 天前
@huagequan $ sudo apt policy openssh-server
openssh-server:
Installed: 1:8.9p1-3ubuntu0.10
Candidate: 1:8.9p1-3ubuntu0.10
Version table:
*** 1:8.9p1-3ubuntu0.10 500
500 http://archive.ubuntu.com/ubuntu jammy-updates/main amd64 Packages
500 http://security.ubuntu.com/ubuntu jammy-security/main amd64 Packages
100 /var/lib/dpkg/status
1:8.9p1-3 500
500 http://archive.ubuntu.com/ubuntu jammy/main amd64 Packages
Love4Taylor
4 天前

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/1054091

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX