Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-51384

Published: December 20, 2023Last modified: December 20, 2023

Description

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshFixed (9.1_p1-r7)
StreamopensshFixed (9.6_p1-r0)

References

Published BELL-SAs

ON THIS PAGE