CVE-2023-25136

Description from NVD

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

Information Acquisition Date:2023-02-24T14:57Z
CVSS 2.0: 0.0 None CVSS 3.x: 9.8 CRITICAL

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD References

 https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sig
     source:MISC
     tags:Patch    Vendor Advisory    
 https://bugzilla.mindrot.org/show_bug.cgi?id=3522
     source:MISC
     tags:Exploit    Issue Tracking    Third Party Advisory    
 https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946
     source:MISC
     tags:Patch    Third Party Advisory    
 https://www.openwall.com/lists/oss-security/2023/02/02/2
     source:MISC
     tags:Exploit    Mailing List    Third Party Advisory    
 https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/
     source:MISC
     tags:Exploit    Third Party Advisory    
 https://news.ycombinator.com/item?id=34711565
     source:MISC
     tags:Issue Tracking    Third Party Advisory    
 [oss-security] 20230213 Re: double-free vulnerability in OpenSSH server 9.1 (CVE-2023-25136)
     source:MLIST
     tags:
 [oss-security] 20230222 Re: double-free vulnerability in OpenSSH server 9.1 (CVE-2023-25136)
     source:MLIST
     tags:
 [oss-security] 20230222 Re: Re: double-free vulnerability in OpenSSH server 9.1 (CVE-2023-25136)
     source:MLIST
     tags:
 [oss-security] 20230223 Re: Re: double-free vulnerability in OpenSSH server 9.1 (CVE-2023-25136)
     source:MLIST
     tags:

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag: Linux(2 tweets) OpenSSL(1 tweets)



List of frequently cited URLs

URLNum of Times Referred to
https://alerts.vulmon.com/?utm_source=twitter&utm_medium=so...222
https://cvetrends.com49
https://news.ycombinator.com/item?id=347115657
https://thehackernews.com/2023/02/openssh-releases-patch-fo...6
https://www.it-connect.fr/openssh-9-1-affecte-par-une-faill...6
https://twitter.com/hack_git/status/16287762246998712335
https://github.com/jfrog/jfrog-CVE-2023-25136-OpenSSH_Doubl...4
https://blog.qualys.com/vulnerabilities-threat-research/202...4
https://jfrog.com/blog/openssh-pre-auth-double-free-cve-202...3
https://seclists.org/oss-sec/2023/q1/923
https://frycos.github.io/vulns4free/2023/02/06/goanywhere-f...3
https://www.da.vidbuchanan.co.uk/blog/exploiting-acropalyps...3

▼ Show Information from Twitter(19)


List of frequently cited URLs

URLNum of Times Referred to
alerts.vulmon.com222
cvetrends.com49
news.ycombinator.com7
thehackernews.com6
www.it-connect.fr6
twitter.com5
github.com4
blog.qualys.com4
jfrog.com3
seclists.org3
frycos.github.io3
www.da.vidbuchanan.co.uk3

▼ Show Information from Twitter(19)


GitHub Search Results: Up to 10
NameURL
Christbowel/CVE-2023-25136 https://github.com/Christbowel/CVE-2023-25136
jfrog/jfrog-CVE-2023-25136-OpenSSH_Double-Free https://github.com/jfrog/jfrog-CVE-2023-25136-OpenSSH_Double-Free
ticofookfook/CVE-2023-25136 https://github.com/ticofookfook/CVE-2023-25136

GitHub Search Results: Up to 10
NameURL
Christbowel/CVE-2023-25136 github.com
jfrog/jfrog-CVE-2023-25136-OpenSSH_Double-Free github.com
ticofookfook/CVE-2023-25136 github.com

2023/04/18 Score : 0
Added Har-sia Database : 2023/02/03
Last Modified : 2023/04/18
Highest Scored Date : 2023/02/09
Highest Score : 60