Advisories ยป MGASA-2021-0261

Updated openssh packages fix a security vulnerability

Publication date: 16 Jun 2021
Modification date: 16 Jun 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-28041

Description

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a 
few less-common scenarios, such as unconstrained agent-socket access on a 
legacy operating system, or the forwarding of an agent to an 
attacker-controlled host (CVE-2021-28041). 
                

References

SRPMS

8/core