OpenBSD OpenSSH 9.9 Patch 2

CPE Details

OpenBSD OpenSSH 9.9 Patch 2
9.9
2025-04-04
19h24 +00:00
2025-04-04
19h24 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:openbsd:openssh:9.9:p2:*:*:*:*:*:*

Informations

Vendor

openbsd

Product

openssh

Version

9.9

Update

p2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-51767 2023-12-23 23h00 +00:00 OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
7
Haute
CVE-2008-3844 2008-08-27 18h00 +00:00 Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.
9.3
CVE-2007-2768 2007-05-21 18h00 +00:00 OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.
4.3