/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-38408

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-38408

CGA ID

CGA-wfw4-m8r2-5q9c

Severity

9.8

Critical

CVSS V3

Description

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images