Thanks for using the TrueNAS Community Edition issue tracker! TrueNAS Enterprise users receive direct support for their reports from our support portal.

Issues

Select view

Select search mode

 
50 of

CVE-2024-6387 openssh RCE vulnerability

Complete

Description

CVE-2024-6387 openssh RCE vulnerability was reported July 1, 2024.
See
Technical discussion with high detail and analysis: https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt

SCALE and CORE are both affected.
SCALE fix: 1:9.2p1-2+deb12u3

CORE fix: https://security.freebsd.org/advisories/FreeBSD-SA-24:04.openssh.asc

Problem/Justification

None

Impact

None

Details

Assignee

Reporter

Labels

Impact

Critical

Components

Priority

More fields

Katalon Platform

Created July 1, 2024 at 1:49 PM
Updated August 22, 2024 at 1:06 PM
Resolved July 2, 2024 at 5:31 PM

Activity

Show:

Bug ClerkJuly 2, 2024 at 5:31 PM

This issue has now been closed. Comments made after this point may not be viewed by the TrueNAS Teams. Please open a new issue if you have found a problem or need to re-engage with the TrueNAS Engineering Teams.

Bug ClerkJuly 2, 2024 at 5:25 PM
Edited

13.3 PR: https://github.com/truenas/ports/pull/1342

updates security/openssh-portable


Can be validated via `pkg info openssh-portable`

Older version is 9.6p1_1,1

Bug ClerkJuly 2, 2024 at 1:57 PM
Edited

13.0 PR: https://github.com/truenas/ports/pull/1341

updates security/openssh-portable

This can be validated through pkg info openssh-portable

Older version is 8.8.p1_1,1

Andrew WalkerJuly 2, 2024 at 1:12 PM

Ports fixes pending.

Bug ClerkJuly 2, 2024 at 11:29 AM

Flag notifications