Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-38408
HistoryJul 20, 2023 - 3:15 a.m.

Remote code execution

2023-07-2003:15:00
PRIOn knowledge base
www.prio-n.com
1101
ssh-agent
pkcs#11
remote code execution
search path
insufficiently trustworthy
attacker-controlled system
incomplete fix
cve-2016-10009

9.1 High

AI Score

Confidence

High

0.102 Low

EPSS

Percentile

95.0%

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

References