Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-28041

Опубликовано: 05 мар. 2021
Источник: debian
EPSS Низкий

Описание

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshfixed1:8.4p1-5package
opensshnot-affectedbusterpackage
opensshnot-affectedstretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2021/03/03/1

  • https://github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568db

  • https://ftp.openbsd.org/pub/OpenBSD/patches/6.8/common/015_sshagent.patch.sig

EPSS

Процентиль: 44%
0.00213
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 4 лет назад

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

CVSS3: 7.1
redhat
больше 4 лет назад

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

CVSS3: 7.1
nvd
больше 4 лет назад

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

CVSS3: 7.1
msrc
больше 4 лет назад

Описание отсутствует

suse-cvrf
больше 3 лет назад

Security update for openssh

EPSS

Процентиль: 44%
0.00213
Низкий