[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

openssh: double-free memory corruption may lead to arbitrary code execution (CVE-2021-28041)

ID: oval:org.secpod.oval:def:1801875Date: (C)2021-03-30   (M)2023-11-10
Class: PATCHFamily: unix




A double-free memory corruption, introduced in OpenSSH 8.2, that could be reached by an attacker with access to the agent socket. Exploitable by a user forwarding an agent either to an account shared with a malicious user or to a host with an attacker holding root access.

Platform:
Alpine Linux 3.12
Alpine Linux 3.13
Product:
openssh
Reference:
12514
CVE-2021-28041
CVE    1
CVE-2021-28041
CPE    1
cpe:/a:openbsd:openssh

© SecPod Technologies