VYPR

rpm package

almalinux/pam_ssh_agent_auth

pkg:rpm/almalinux/pam_ssh_agent_auth

Vulnerabilities (22)

  • CVE-2021-41617HigSep 26, 2021
    affected < 0.10.3-7.13.el8fixed 0.10.3-7.13.el8

    sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges

  • CVE-2020-15778HigJul 24, 2020
    affected < 0.10.3-7.24.el8fixed 0.10.3-7.24.el8

    scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that

Page 2 of 2