QID 38867

Date Published: 2022-05-25

QID 38867: OpenSSH Double Free Vulnerability

OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.

Affected Versions:
OpenSSH before 8.5

QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.

Attacker can access the legacy operating system, or forward the agent to an attacker-controlled host.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to upgrade to OpenSSH 8.5 or later to remediate these vulnerabilities.
    Vendor References

    CVEs related to QID 38867

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-28041 URL Logo www.openssh.com/txt/release-8.5