You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2023-51384: In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
CVE-2023-51385: In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Note: the openssh 9.6 PR was already merged, but it did not have the 2 CVEs. We just need to add the missing CVEs.
Name: openssh
CVEs: CVE-2023-51384, CVE-2023-51385
CVSSs: 5.5, 6.5
Action Needed: update to >= 9.6
Summary:
Note: the openssh 9.6 PR was already merged, but it did not have the 2 CVEs. We just need to add the missing CVEs.
refmap.gentoo: https://bugs.gentoo.org/920722
The text was updated successfully, but these errors were encountered: