Back

HIGH

openssh: loading of untrusted PKCS#11 modules in ssh-agent

Published Jan 5, 2017

Description

Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.

Affected products

Remediation

Red Hat statement

In order to exploit this flaw, the attacker needs to have control of the forwarded agent-socket and the ability to write to the filesystem of the host running ssh-agent. Because of this restriction for successful exploitation, this issue has been rated as having Moderate security impact. A future update may address this flaw.

Metrics

Weaknesses (1)

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 5, 2017
Updated May 29, 2026
Reserved Dec 19, 2016
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 19, 2016