The Pakistan Telecommunication Authority (PTA) has issued a Cyber Security Advisory regarding a critical vulnerability in OpenSSH’s server component on Linux systems.
The flaw, known as CVE-2024-6387, or “regreSSHion”, enables unauthenticated remote code execution (RCE) with root privileges, posing a significant threat of complete system compromise.
OpenSSH versions 8.5p1 through 9.7p1 are impacted by this vulnerability.
PTA advises OpenSSH users to upgrade to the recent version (9.8p1) and take additional security measures to prevent exploitation.