Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-51384

Опубликовано: 18 дек. 2023
Источник: debian
EPSS Низкий

Описание

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshfixed1:9.6p1-1package
opensshfixed1:9.2p1-2+deb12u2bookwormpackage
opensshnot-affectedbullseyepackage
opensshnot-affectedbusterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2023/12/18/2

  • https://github.com/openssh/openssh-portable/commit/881d9c6af9da4257c69c327c4e2f1508b2fa754b (V_9_6_P1)

EPSS

Процентиль: 13%
0.00044
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 1 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

CVSS3: 5.5
redhat
больше 1 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

CVSS3: 5.5
nvd
больше 1 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

CVSS3: 5.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.5
github
больше 1 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

EPSS

Процентиль: 13%
0.00044
Низкий