ECHO-3041-f7d2-3868

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-3041-f7d2-3868.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-3041-f7d2-3868
Upstream
Withdrawn
2025-08-03T16:59:07Z
Published
2025-08-29T01:37:38Z
Modified
2026-09-15T00:57:40Z
Summary
Upstream does not consider this a bug underlying in OpenSSH and does not intent to address it in OpenSSH. Additionally, this attack was not demonstrated against stock OpenSSH, and has never been demonstrated to be exploitable in a real software configuration. https://security-tracker.debian.org/tracker/CVE-2023-51767 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059393 https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1
Details
References

Affected packages

Echo / openssh

Package

Name
openssh
Purl
pkg:deb/echo/openssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:9.2p1-2+deb12u6

Database specific

source
"https://advisory.echohq.com/osv/ECHO-3041-f7d2-3868.json"