poky/meta/recipes-connectivity
Archana Polampalli e01d123ba1 openssh: fix CVE-2023-38408
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an
insufficiently trustworthy search path, leading to remote code
execution if an agent is forwarded to an attacker-controlled system.
(Code in /usr/lib is not necessarily safe for loading into ssh-agent.)
NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-38408

Upstream patches:
892506b136
1f2731f5d7
29ef8a0486
099cdf59ce

(From OE-Core rev: 3c01159ab6a843fc922cf779b022c965d4ecd453)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2023-08-02 04:47:13 -10:00
..
2023-05-30 04:11:15 -10:00
2021-11-10 19:27:28 +00:00
2022-11-24 15:30:01 +00:00
2022-02-12 17:05:35 +00:00
2022-11-24 15:30:01 +00:00
2022-05-04 13:07:34 +01:00
2023-08-02 04:47:13 -10:00
2023-06-14 04:16:59 -10:00
2023-02-04 23:32:20 +00:00
2021-08-02 15:44:10 +01:00
2022-12-07 15:02:45 +00:00
2022-11-24 15:30:00 +00:00