Hi Team, We are reaching out to inquire about the reported vulnerabilities in the OpenSSH version (openssh.x86_64 8.7p1-34.el9_3.3) on AlmaLinux 9.We would like to know whether the fixes are included same like redaht in the version of openssh.x86_64 8.7p1-34.el9_3.3? CVE-2023-48795, CVE-2023-51385 and CVE-2023-51384. Thanks & Regards, Sujith P K CIO Global Server Management [Shape Description automatically generated with medium confidence] 3rd Floor, Wing B WTC2 Bagmane World Technology Center SEZ Marathahalli Outer Ring Road, Mahadevapura, Bangalore 560 048, India [cid:image002.gif@01DA970B.9E2E2670]mailto: +91- 8971692387 | sujith.pk@mphasis.commailto:sujith.pk@mphasis.com www.mphasis.comhttp://www.mphasis.com/ Information Transmitted by this Email is Proprietary to Mphasis, its Associated Companies and/or its Customers and is Intended for use only by the Individual or Entity to which it is Addressed, and may contain Information that is Privileged, Confidential or Exempt from Disclosure under Applicable Law. If you are not the Intended Recipient or it appears that this Email has been Forwarded to you without proper Authority, you are Notified that any use or Dissemination of this Information in any manner is Strictly Prohibited. In such cases, please Notify us Immediately at mailmaster@mphasis.com and delete this Email from your Records.
Hi Team,
Any updates on this query?
Thanks in advance!
Regards,
Sujith P K
Get Outlook for Androidhttps://aka.ms/AAb9ysg
________________________________
From: Sujith PK
Sent: Thursday, April 25, 2024 12:25:12 PM
To: security@lists.almalinux.org
Yes, both CVE-2023-48795 and CVE-2023-51385 are fixed in openssh.x86_64 8.7p1-34.el9_3.3 as indicated in https://errata.almalinux.org/9/ALSA-2024-1130.html. CVE-2023-51384, however, does not affect el9 distributions as described here https://access.redhat.com/security/cve/cve-2023-51384. FYI, https://errata.almalinux.org supports searching by CVE number, and it's in sync with AlmaLinux repos, so most of the time is the first place to look at ;) Hope it helps, Javi
participants (2)
-
Javier Hernández
-
Sujith PK