CVE-2023-38408 | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
- 🔗 news.ycombinator.com/item
- 🔗 blog.qualys.com/vulnerabilities-threat-research/2023/07/1…
- 🔗 www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-for…
- 🔗 github.com/openbsd/src/commit/f8f5a6b003981bb824329d…
- 🔗 github.com/openbsd/src/commit/7bc29a9d5cd697290aa056…
- 🔗 github.com/openbsd/src/commit/f03a4faa55c4ce08183247…
- 🔗 www.openssh.com/txt/release-9.3p2
- 🔗 www.openssh.com/security.html
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-24 | 2026-10-08 |
|---|---|---|
| ≥90 % | 484 | 342 |
| ≥50 % | 1436 | 1061 |
| ≥10 % | 16 | 2 |
| <10 % | 30 | 562 |
CVE-2023-38408 | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe fo
Noch keine Analyse zu CVE-2023-38408
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.