4 ms·
Patch out for Debian 12; Debian 11 not affected. https://security-tracker.debian.org/tracker/CVE-2024-6387 https://security-tracker.debian.org/tracker/CVE-2024
by 0x0 2y ago
Patch out for Debian 12; Debian 11 not affected.
https://security-tracker.debian.org/tracker/CVE-2024-6387 https://security-tracker.debian.org/tracker/CVE-2024-6387
- nubinetwork 2y agoCan confirm, Pi OS bullseye also has the updated openssh.
- wiredfool 2y agoLooks like Focal (20.04) isn't on an affected version. Jammy (22.04) looks like it is.
- feurio 2y agoMy procrastination pays off ...
- medguru 2y agoAs do theirs ;)
- deleted 2y ago[deleted]
- metadat 2y agoWhat about, uh, 18.04? Edit: 18.04 Bionic is unaffected, the ssh version is 7.6 which is too old.
- creshal 2y agoIf you have extended support: Just update (if it's not so old that it's not even affected in the first place) If you don't have extended support: You're vulnerable to worse, easier to exploit bugs :)
- metadat 2y agoI can confirm this 18.04 machine still gets some important updates like kernel upgrades and patched versions of Apache.
- l33tman 2y agoI have a single 18.04 machine that is stuck on that, because it has 18.04 386, and as 20.04 doesn't support 386 anymore, apparently there is not a simple upgrade path to 20.04 64-bit (without doing extensive surgery). Very annoying...
- urza 2y agoOn 22.04 apt update && upgrade doesn't help.. yet?
- theandrewbailey 2y agoJust ran an apt update and upgrade on my Debian 12 server. OpenSSH packages were the only ones upgraded.
- hgs3 2y agoYes, the Debian 12 fix is out. You can verify you're patched by running 'ssh -V' and verifying you see 'deb12u3'. If you see 'deb12u2' then you're vulnerable [1]. [1] https://security-tracker.debian.org/tracker/CVE-2024-6387 https://security-tracker.debian.org/tracker/CVE-2024-6387