OpenSSH < 9.9p2 DoS

msayyad
New Contributor

Does anyone know how to fix this vulnerability on Mac without installing homebrew on machine ? 

4 REPLIES 4

AJPinto
Esteemed Contributor

Installing it through Homebrew will not help, as that installs a separate SSH binary and does not update the one bundled in with macOS.

Do you have a link to the vulnerability or the NIST details? We disabled SSH years ago on macOS due to vulnerabilities and Apple being very slow to patch SSH.

msayyad
New Contributor

Don't have NIST details. But hope this will help you. https://www.openssh.com/txt/release-9.9p2

Shyamsundar
Valued Contributor

if I am not wrong, even though you install with Homebrew it will not patch the existing one, it will install a new one with the latest version, you need to wait for Apple to release an update, did you tried it with the latest beta version 15.4 beta 3 and check the openSSh version

msayyad
New Contributor

Yes tried with 15.3 it shows SSH 9.8 version