Logo
vulnerabilityCVE-2023-6004
Name
CVE-2023-6004
Source
NVD ( link)Debian ( link)
Description
A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh
Patched

Vulnerability Ratings#


4.8
CVSSv31
4.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
openwrt
openwrt-25.12
0.11.3-r1
Not Affected
yocto
master
0.11.4
Not Affected
yocto
scarthgap
0.10.6
Not Affected

Resolved with patches#


libssh (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2023-6004: options: Simplify the hostname parsing in
Norbert Pocs <norbertpocs0@gmail.com>
CVE-2023-6004
2
CVE-2023-6004 misc: Add ipv6 link-local check for an ip
Norbert Pocs <norbertpocs0@gmail.com>
CVE-2023-6004
3
CVE-2023-6004: config_parser: Allow multiple '@' in usernames
Norbert Pocs <norbertpocs0@gmail.com>
CVE-2023-6004
4
CVE-2023-6004: misc: Add function to check allowed characters
Norbert Pocs <norbertpocs0@gmail.com>
CVE-2023-6004
5
CVE-2023-6004: config_parser: Check for valid syntax of a
Norbert Pocs <norbertpocs0@gmail.com>
CVE-2023-6004
6
Fix regression in IPv6 addresses in hostname parsing
Jakub Jelen <jjelen@redhat.com>
CVE-2023-6004