rpm package
suse/openssh&distro=SUSE Enterprise Storage 7
pkg:rpm/suse/openssh&distro=SUSE%20Enterprise%20Storage%207
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-38408 | — | < 8.1p1-150200.5.37.1 | 8.1p1-150200.5.37.1 | Jul 20, 2023 | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this is | ||
| CVE-2021-41617 | Hig | 7.0 | < 8.1p1-5.21.1 | 8.1p1-5.21.1 | Sep 26, 2021 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges |
- CVE-2023-38408Jul 20, 2023affected < 8.1p1-150200.5.37.1fixed 8.1p1-150200.5.37.1
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this is
- affected < 8.1p1-5.21.1fixed 8.1p1-5.21.1
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges