Topic starter
Description:-
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Â
References
- https://www.openwall.com/lists/oss-security/2023/03/15/8 Â
- https://security.netapp.com/advisory/ntap-20230413-0008/ Â
- security.gentoo.org: GLSA-202307-01Â
- debian.org: DSA-5586Â
- lists.fedoraproject.org: FEDORA-2024-2aac54ebb7Â
Â
Â
Posted : 07/05/2024 4:23 pm
A vulnerability disclosed under CVE-2023-28531 states that ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. Exploiting this vulnerability could lead to the disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Posted : 15/10/2024 10:18 pm