ZeroHour

CVE-2021-28041

CVSS 3.1
7.1 high
EPSS
3%p88
Published
()
Modified
Description

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

Vendors
openbsdfedoraprojectnetapporacle
Products
openssh, fedora, cloud backup, hci management node, solidfire, hci compute node firmware, hci storage node firmware, communications offline mediation controller, zfs storage appliance
Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.