Openssh Portable



OpenSSH is the premier connectivity tool for remote login with the SSH protocol. Parallels desktop on m1. It encrypts all traffic to eliminate eavesdropping, connection hijacking, and other attacks. In addition, OpenSSH provides a large suite of secure tunneling capabilities, several authentication methods,. Oct 19, 2015 Our objective was to not only port OpenSSH so that it worked well on Windows, but to openly contribute those changes back into the portable version of OpenSSH. Of the many options available, one clearly stood out: the previous work that NoMachine had already published in bringing OpenSSH to Windows. The NoMachine port was based on OpenSSH 5.9.

Hard

Current Description

Portable

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.


Analysis Description

Openssh Portable

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

Severity

CVSS 3.x Severity and Metrics:
NIST:NVD
Openssh Portable
Vector:NVD
Openssh Portable
Vector:HyperlinkResourcehttps://github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568dbPatchThird Party Advisoryhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXST2CML2MWY3PNVUXX7FFJE3ATJMNVZ/Third Party Advisoryhttps://security.netapp.com/advisory/ntap-20210416-0002/Third Party Advisoryhttps://www.openssh.com/security.htmlNot ApplicableVendor Advisoryhttps://www.openssh.com/txt/release-8.5Release NotesVendor Advisoryhttps://www.openwall.com/lists/oss-security/2021/03/03/1Mailing ListPatchThird Party Advisory

Weakness Enumeration

CWE-IDCWE NameSource
CWE-415Double FreeNIST

Known Affected Software Configurations Switch to CPE 2.2

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Openssh Portable Binary

Change History

6 change records found show changes