-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
(also fix publish dates on previous)
- Loading branch information
Showing
4 changed files
with
32 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1 +1 @@ | ||
2023-8 | ||
2023-9 |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
id: MNBSD-2023-9 | ||
summary: OpenSSH ssh-agent insecure search path | ||
details: The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. | ||
affected: | ||
- package: | ||
name: openssh | ||
ecosystem: MidnightBSD | ||
ranges: | ||
- type: ECOSYSTEM | ||
events: | ||
- introduced: 3.1.0 | ||
- fixed: 3.2.0 | ||
versions: | ||
- 3.1.0 | ||
- 3.1.1 | ||
- 3.1.2 | ||
- 3.1.3 | ||
- 3.1.4 | ||
references: | ||
- type: WEB | ||
url: https://nvd.nist.gov/vuln/detail/CVE-2023-38408 | ||
- type: WEB | ||
url: https://nvd.nist.gov/vuln/detail/CVE-2016-10009 | ||
aliases: | ||
- CVE-2023-38408 | ||
modified: "2023-12-27T00:00:00.000Z" | ||
published: "2023-12-27T00:00:00.000Z" |