Lucene search

K
freebsdFreeBSDF1A00122-3797-11EF-B611-84A93843EB75
HistoryJul 01, 2024 - 12:00 a.m.

OpenSSH -- Race condition resulting in potential remote code execution

2024-07-0100:00:00
vuxml.freebsd.org
43
openssh
race condition
remote code execution
root access
unix

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.004

Percentile

73.8%

The OpenSSH project reports:

A race condition in sshd(8) could allow remote code execution as root on non-OpenBSD systems.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchopenssh-portable< 9.7.p1_2,1UNKNOWN
FreeBSDanynoarchfreebsd= 14.1UNKNOWN
FreeBSDanynoarchfreebsd< 14.1_2UNKNOWN

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.004

Percentile

73.8%