VDB
BDU%3A2024-00107
BDU%3A2024-00107
PUBLISHED
CVSS 6 MEDIUM
Уязвимость функции mm_answer_authpassword() cредства криптографической защиты OpenSSH, позволяющая нарушителю реализовать атаку Rowhammer и обойти процедуру аутентификации
Risk Scores
CVSS 2.0
6
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, OpenBSD Project | Red Hat Enterprise Linux, Debian GNU/Linux, OpenSSH |
Timeline
- Jan 10, 2024 CVE Published
References
- https://arxiv.org/abs/2309.02545 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2255850 url
- https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77 url
- https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878 url
- https://vuldb.com/?id.248943 url
- https://access.redhat.com/security/cve/cve-2023-51767 url
- https://groups.google.com/g/linux.debian.bugs.dist/c/vcBj57_jMRU url
- https://github.com/CMU-SAFARI/ABACuS advisory
- https://security-tracker.debian.org/tracker/CVE-2023-51767 advisory
- https://access.redhat.com/security/cve/CVE-2023-51767 advisory