QID 198291

Date Published: 2021-03-23

QID 198291: Ubuntu Security Notification for Openssh Vulnerability (USN-4762-1)

It was discovered that the OpenSSH ssh-agent incorrectly handled memory.

A remote attacker able to connect to the agent could use this issue to cause it to crash, resulting in a denial of service, or possibly execute arbitrary code.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Ubuntu advisory USN-4762-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198291

    Software Advisories
    Advisory ID Software Component Link
    USN-4762-1 20.04 (focal) on src openssh-client URL Logo launchpad.net/ubuntu/+source/openssh/1:8.2p1-4ubuntu0.2
    USN-4762-1 20.10 (groovy) on src openssh-client URL Logo launchpad.net/ubuntu/+source/openssh/1:8.3p1-1ubuntu0.1