Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Nasty regreSSHion bug in OpenSSH puts roughly 700K Linux boxes at risk
The Register ^ | 1 July 2024 | Connor Jones

Posted on 07/02/2024 10:59:45 AM PDT by ShadowAce

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-56 next last
To: ShadowAce

“Since I posted this a few minutes ago, I checked my available updates, and my distro already has the newest package ready to DL with the fix.

I love Open Source!”

And it wasn’t packaged with 20 other garbage downloads that break other stuff at the same time. :)

MS, fix one issue while creating five others.


21 posted on 07/03/2024 7:02:32 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ShadowAce

Ok, thanks. I’m not too versed in commands and such- but will try them when needed- have had to do several when things went awry- or when installing some program not in the app repository.


22 posted on 07/03/2024 7:14:45 AM PDT by Bob434
[ Post Reply | Private Reply | To 19 | View Replies]

To: Openurmind

You use mint dont you? If so, I’ll check the update app again- maybe they have it there today


23 posted on 07/03/2024 7:16:32 AM PDT by Bob434
[ Post Reply | Private Reply | To 21 | View Replies]

To: Bob434

Yes, there is one Ubuntu security update in there but it doesn’t have any references to what the patch is for... I’m sure they are top of it... Or our version is new enough we don’t have to worry. In which case we will not see a security update for this particular issue.


24 posted on 07/03/2024 7:20:51 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 23 | View Replies]

To: dayglored

Thank you. Will give it a go tonight.


25 posted on 07/03/2024 7:21:40 AM PDT by Bob434
[ Post Reply | Private Reply | To 16 | View Replies]

To: Openurmind

Ok thanks- im pretty sure I run the newest mint- but will check when I get home.


26 posted on 07/03/2024 7:22:40 AM PDT by Bob434
[ Post Reply | Private Reply | To 24 | View Replies]

To: ShadowAce

I run OpenSUSE 15.5. Here is their statement:

“Only SUSE Linux Enterprise 15 SP6, SUSE Linux Micro 6.0, openSUSE Leap 15.6 and openSUSE Tumbleweed were affected by this problem.”


27 posted on 07/03/2024 7:40:40 AM PDT by steve86 (Numquam accusatus, numquam ad curiam ibit, numquam ad carcerem™)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

ran the command and it said SSh wasn’t installed, so my system wouldn’t be vulnerable then?


28 posted on 07/03/2024 8:09:52 AM PDT by Bob434
[ Post Reply | Private Reply | To 16 | View Replies]

To: Bob434
ran the command and it said SSh wasn’t installed, so my system wouldn’t be vulnerable then?

That would be correct. You're good to go.

29 posted on 07/03/2024 8:22:21 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 28 | View Replies]

To: Bob434
> ran the command and it said SSh wasn’t installed, so my system wouldn’t be vulnerable then?

Yep. SSH (OpenSSH) is optional on many systems, especially if they have a desktop GUI interface. If it's not installed, it certainly can't cause trouble. :-)

30 posted on 07/03/2024 8:24:15 AM PDT by dayglored (Strange Women Lying In Ponds Distributing Swords! Arthur Pendragon in 2024)
[ Post Reply | Private Reply | To 28 | View Replies]

To: ShadowAce

Thanks- i have lots to learn about linux still


31 posted on 07/03/2024 8:47:40 AM PDT by Bob434
[ Post Reply | Private Reply | To 29 | View Replies]

To: dayglored

thanks- i forget that soem of the posts on linux are abotu servers or systems with other stuff on them-


32 posted on 07/03/2024 8:48:41 AM PDT by Bob434
[ Post Reply | Private Reply | To 30 | View Replies]

To: dayglored

well that is weird- i checked with ssh -V and came up with

“OpenSSH_8.9p1 Ubuntu-3ubuntu0.10, OpenSSL 3.0.2 15 Mar 2022”

when i run sshd —help - i get

“Command ‘sshd’ not found, but can be installed with:
sudo apt install openssh-server”


33 posted on 07/03/2024 9:01:17 AM PDT by Bob434
[ Post Reply | Private Reply | To 30 | View Replies]

To: ShadowAce

Not in the Windple duopoly?

We’ll get you, our little pretties!


34 posted on 07/03/2024 9:02:49 AM PDT by 9YearLurker
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

ok now im confused-

it seems i have the client when i check with ssh -V

but not the server when i check with sshd -V

woudl i have to have both in order to be vulnerable to the exploit?


35 posted on 07/03/2024 9:08:15 AM PDT by Bob434
[ Post Reply | Private Reply | To 30 | View Replies]

To: Bob434

No—I think you are safe.


36 posted on 07/03/2024 10:21:44 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 35 | View Replies]

To: ShadowAce; Bob434

Roger that. The sshd server is the vulnerable component.


37 posted on 07/03/2024 10:28:43 AM PDT by dayglored (Strange Women Lying In Ponds Distributing Swords! Arthur Pendragon in 2024)
[ Post Reply | Private Reply | To 36 | View Replies]

To: Bob434

the client (ssh) allows you to connect via ssh to other computers
the server (sshd) allows others to connect to your system, so if you don’t have the server no one can connect to you. If you don’t need it, you shouldn’t have it :-)


38 posted on 07/03/2024 11:28:19 AM PDT by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: zeugma

ah ok, thanks, sorry for the late reply-


39 posted on 07/03/2024 7:10:49 PM PDT by Bob434
[ Post Reply | Private Reply | To 38 | View Replies]

To: dayglored

Great- thanks for helping- this stuff is confusing to me these days


40 posted on 07/03/2024 7:11:30 PM PDT by Bob434
[ Post Reply | Private Reply | To 37 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-56 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson