CVE-2021-28041
05.03.2021, 21:15
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openbsd | openssh | 8.2 ≤ 𝑥 < 8.5 |
| netapp | cloud_backup | - |
| netapp | hci_management_node | - |
| netapp | solidfire | - |
| netapp | hci_compute_node_firmware | - |
| netapp | hci_storage_node_firmware | - |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
| oracle | zfs_storage_appliance | 8.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References