Topic starter
Description:-
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
References
- https://www.openwall.com/lists/oss-security/2023/03/15/8
- https://security.netapp.com/advisory/ntap-20230413-0008/
- security.gentoo.org: GLSA-202307-01
- debian.org: DSA-5586
- lists.fedoraproject.org: FEDORA-2024-2aac54ebb7
Posted : 07/05/2024 4:23 pm