USN-7443-3

Source
https://ubuntu.com/security/notices/USN-7443-3
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7443-3.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7443-3
Upstream
Related
Published
2025-07-17T13:12:01.694478Z
Modified
2025-10-13T04:41:01Z
Summary
erlang vulnerability
Details

USN-7443-1 fixed a vulnerability in Erlang. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.

Original advisory details:

Fabian Bäumer, Marcel Maehren, Marcus Brinkmann, and Jörg Schwenk discovered that Erlang OTP’s SSH module incorrect handled authentication. A remote attacker could use this issue to execute arbitrary commands without authentication, possibly leading to a system compromise.

References

Affected packages

Ubuntu:Pro:16.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:18.3-dfsg-1ubuntu3.1+esm1?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:18.3-dfsg-1ubuntu3.1+esm1

Affected versions

1:18.*

1:18.0-dfsg-1ubuntu1
1:18.0-dfsg-1ubuntu2
1:18.2-dfsg-2ubuntu1
1:18.3-dfsg-1ubuntu1
1:18.3-dfsg-1ubuntu2
1:18.3-dfsg-1ubuntu3
1:18.3-dfsg-1ubuntu3.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-asn1"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-base"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-base-hipe"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-common-test"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-corba"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-crypto"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-debugger"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-dev"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-dialyzer"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-diameter"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-edoc"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-eldap"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-erl-docgen"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-et"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-eunit"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-examples"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-gs"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-ic"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-ic-java"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-inets"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-jinterface"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-manpages"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-megaco"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-mnesia"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-mode"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-nox"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-observer"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-odbc"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-os-mon"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-parsetools"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-percept"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-public-key"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-reltool"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-runtime-tools"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-snmp"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-src"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-ssh"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-ssl"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-syntax-tools"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-test-server"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-tools"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-typer"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-webtool"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-wx"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-x11"
        },
        {
            "binary_version": "1:18.3-dfsg-1ubuntu3.1+esm1",
            "binary_name": "erlang-xmerl"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

{
    "cves_map": {
        "cves": [
            {
                "severity": [
                    {
                        "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "type": "CVSS_V3"
                    },
                    {
                        "score": "high",
                        "type": "Ubuntu"
                    }
                ],
                "id": "CVE-2025-32433"
            }
        ],
        "ecosystem": "Ubuntu:Pro:16.04:LTS"
    }
}

Ubuntu:Pro:18.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:20.2.2+dfsg-1ubuntu2+esm1?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:20.2.2+dfsg-1ubuntu2+esm1

Affected versions

1:20.*

1:20.0.4+dfsg-1ubuntu1
1:20.1.2+dfsg-1ubuntu1
1:20.1.3+dfsg-1ubuntu1
1:20.1.4+dfsg-1ubuntu1
1:20.1.5+dfsg-1ubuntu1
1:20.1.6+dfsg-1ubuntu1
1:20.1.7+dfsg-1ubuntu1
1:20.2.1+dfsg-1ubuntu1
1:20.2.2+dfsg-1ubuntu1
1:20.2.2+dfsg-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-asn1"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-base"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-base-hipe"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-common-test"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-corba"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-crypto"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-debugger"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-dev"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-dialyzer"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-diameter"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-edoc"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-eldap"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-erl-docgen"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-et"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-eunit"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-examples"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-ic"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-ic-java"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-inets"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-jinterface"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-manpages"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-megaco"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-mnesia"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-mode"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-nox"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-observer"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-odbc"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-os-mon"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-parsetools"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-public-key"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-reltool"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-runtime-tools"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-snmp"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-src"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-ssh"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-ssl"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-syntax-tools"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-tools"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-wx"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-x11"
        },
        {
            "binary_version": "1:20.2.2+dfsg-1ubuntu2+esm1",
            "binary_name": "erlang-xmerl"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

{
    "cves_map": {
        "cves": [
            {
                "severity": [
                    {
                        "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "type": "CVSS_V3"
                    },
                    {
                        "score": "high",
                        "type": "Ubuntu"
                    }
                ],
                "id": "CVE-2025-32433"
            }
        ],
        "ecosystem": "Ubuntu:Pro:18.04:LTS"
    }
}