Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: openssh #1133

Closed
dongsupark opened this issue Jul 24, 2023 · 0 comments · Fixed by flatcar/scripts#1022
Closed

update: openssh #1133

dongsupark opened this issue Jul 24, 2023 · 0 comments · Fixed by flatcar/scripts#1022
Assignees
Labels
advisory security advisory channel/alpha Issue concerns the Alpha channel. channel/beta Issue concerns the Beta channel. cvss/CRITICAL >= 9 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

dongsupark commented Jul 24, 2023

Name: openssh
CVEs: CVE-2023-38408
CVSSs: 9.8
Action Needed: update to >= 9.3_p2

Summary: The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

See also https://seclists.org/oss-sec/2023/q3/49.

refmap.gentoo: https://bugs.gentoo.org/910553

@dongsupark dongsupark added security security concerns advisory security advisory channel/alpha Issue concerns the Alpha channel. channel/beta Issue concerns the Beta channel. labels Jul 24, 2023
@dongsupark dongsupark self-assigned this Jul 27, 2023
@dongsupark dongsupark added the cvss/CRITICAL >= 9 assessed CVSS label Aug 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory channel/alpha Issue concerns the Alpha channel. channel/beta Issue concerns the Beta channel. cvss/CRITICAL >= 9 assessed CVSS security security concerns
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant