CVE-2023-38408

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
20/07/2023
Last modified:
15/10/2024

Description

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* 9.3 (excluding)
cpe:2.3:a:openbsd:openssh:9.3:-:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:9.3:p1:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools