The PKCS#11 feature in ssh-agent in... CVE-2023-38408

- AV AC AU C I A
发布: 2023-07-20
修订: 2024-04-04

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

0%
暂无可用Exp或PoC
当前有5条受影响产品信息