Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-51385
Description:In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2024.0603.1   1.3.6.1.4.1.25623.1.1.12.2024.6560.3   1.3.6.1.4.1.25623.1.1.4.2024.0596.1   1.3.6.1.4.1.25623.1.1.18.2.2024.0596.1   1.3.6.1.4.1.25623.1.1.1.1.2023.5586   1.3.6.1.4.1.25623.1.1.4.2024.0604.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-51385
Debian Security Information: DSA-5586 (Google Search)
https://www.debian.org/security/2023/dsa-5586
http://seclists.org/fulldisclosure/2024/Mar/21
https://security.gentoo.org/glsa/202312-17
https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a
https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html
https://www.openssh.com/txt/release-9.6
https://www.openwall.com/lists/oss-security/2023/12/18/2
https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
http://www.openwall.com/lists/oss-security/2023/12/26/4




© 1998-2025 E-Soft Inc. All rights reserved.