In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/2039577 | issue tracking |
https://ubuntu.com/security/notices/USN-6554-1 | vendor advisory |
https://ubuntu.com/security/CVE-2023-5616 | issue tracking |