OESA-2023-1480
Dashboard / Vulnerabilities / OESA-2023-1480
Summary: openssh security update
Details: OpenSSH is the premier connectivity tool for remote login with the SSH protocol. Security Fix(es): The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.(CVE-2023-38408)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1480, https://nvd.nist.gov/vuln/detail/CVE-2023-38408
Affected packages
Package
Name: openssh
Purl: pkg:rpm/openEuler/openssh&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
