OpenSSH Last version in Amazon Linux 2

1

Hi to all,

I'm trying to update OpenSSH Server version in a Amazon Linux 2, to fix some vulnerabilities like CVE-2017-15906 and CVE-2020-15778.

But, to fix it, I need the last version of OpenSSH server, which is 8.6. If I try to do "sudo yum update" and "sudo yum install openssh-server", the last version in the repositories are the 7.4p1.

Anyone know the way to upgrade to the 8.6 version? Many thanks!

已提問 3 年前檢視次數 5092 次
2 個答案
1

Sorry, maybe i don't explain my problem clearly.

My Vulnerability scanner detects and old version of OpenSSH (7.4). Therefore, associate this older version with this vulnerabilities. No detects explicitly the vulnerability, only de older version of OpenSSH.

So I need to update OpenSSH, but Amazon Linux repositories are out of date. Is there any way to update to 8.6 version?

I don't know how to add a new repository to fix this. Any tip?

Thanks

已回答 3 年前
0

CVE-2017-15906 has been resolved as part of https://alas.aws.amazon.com/AL2/ALAS-2018-1042.html.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15778 is disputed by the vendor, so no fix has been published for that yet.

Amazon Linux 2 uses the same process originating from Red Hat Enterprise Linux for stable linux distributions where they do not perform major upgrades of software. They will backport the fixes and keep the same version numbers.

已回答 3 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南