Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:4419

Опубликовано: 08 авг. 2023
Источник: rocky
Оценка: Important

Описание

Important: openssh security update

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • openssh: Remote code execution in ssh-agent PKCS#11 support (CVE-2023-38408)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
opensshx86_6419.el8_8openssh-8.0p1-19.el8_8.x86_64.rpm
openssh-cavsx86_6419.el8_8openssh-cavs-8.0p1-19.el8_8.x86_64.rpm
openssh-clientsx86_6419.el8_8openssh-clients-8.0p1-19.el8_8.x86_64.rpm
openssh-keycatx86_6419.el8_8openssh-keycat-8.0p1-19.el8_8.x86_64.rpm
openssh-ldapx86_6419.el8_8openssh-ldap-8.0p1-19.el8_8.x86_64.rpm
openssh-serverx86_6419.el8_8openssh-server-8.0p1-19.el8_8.x86_64.rpm
pam_ssh_agent_authx86_647.19.el8_8pam_ssh_agent_auth-0.10.3-7.19.el8_8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 2 года назад

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

CVSS3: 9.8
redhat
почти 2 года назад

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

CVSS3: 9.8
nvd
почти 2 года назад

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

CVSS3: 9.8
debian
почти 2 года назад

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insuff ...

suse-cvrf
почти 2 года назад

Security update for openssh