Security Onion and RegreSSHion CVE-2024-6387

Security Onion and RegreSSHion CVE-2024-6387

A vulnerability was recently announced in OpenSSH: https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server https://linux.oracle.com/cve/CVE-2024-6387.html https://linux.oracle.com/errata/ELSA-2024-4312.html https://linux.oracle.com/errata/ELSA-2024-12468.html First, it’s important to note the following from https://isc.sans.edu/diary/SSH+regreSSHion+Remote+Code+Execution+Vulnerability+in+OpenSSH/31046: […]

Read More
Security Onion and the xz Vulnerability

Security Onion and the xz Vulnerability

Recently, a vulnerability was reported in the xz library: https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://www.cve.org/CVERecord?id=CVE-2024-3094 https://nvd.nist.gov/vuln/detail/CVE-2024-3094 https://www.openwall.com/lists/oss-security/2024/03/29/4 https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users Security Onion is NOT affected by […]

Read More
X