Lucene search

K
f5F5F5:K31440025
HistoryJan 24, 2017 - 12:00 a.m.

K31440025 : OpenSSH vulnerability CVE-2016-10009

2017-01-2400:00:00
my.f5.com
99

7.9 High

AI Score

Confidence

High

0.102 Low

EPSS

Percentile

95.0%

Security Advisory Description

Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket. (CVE-2016-10009)
Impact
Running the ssh-agent program requires a local administrator to connect to the system and run the command. Once thessh-agenthas been started, an attacker could run code on the system that is running thessh-agentif the attacker has control of the forwarded agent socket on the host running thesshdserver and can write to the filesystem of the host that is running thessh-agent.