Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 #197

Open
mend-bolt-for-github bot opened this issue Dec 25, 2023 · 5 comments
Open

CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 #197

mend-bolt-for-github bot opened this issue Dec 25, 2023 · 5 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link
Contributor

mend-bolt-for-github bot commented Dec 25, 2023

CVE-2023-51767 - High Severity Vulnerability

Vulnerable Libraries - src3.1.3, src3.1.3

Vulnerability Details

OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.

Publish Date: 2023-12-24

URL: CVE-2023-51767

CVSS 3 Score Details (7.0)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: High
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Dec 25, 2023
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (Medium) detected in srcvendor/unbound/dist/1.19.0, openssh-portableV_9_2_P1 CVE-2023-51767 (Medium) detected in srcvendor/nvi/2.2.1, openssh-portableV_9_6_P1 Dec 26, 2023
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (Medium) detected in srcvendor/nvi/2.2.1, openssh-portableV_9_6_P1 CVE-2023-51767 (Medium) detected in srcvendor/unbound/dist/1.19.0, openssh-portableV_9_2_P1 Dec 27, 2023
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (Medium) detected in srcvendor/unbound/dist/1.19.0, openssh-portableV_9_2_P1 CVE-2023-51767 (Medium) detected in srcvendor/nvi/2.2.1, openssh-portableV_9_6_P1 Dec 27, 2023
@laffer1
Copy link
Member

laffer1 commented Dec 27, 2023

cataloged as MNBSD-2023-12

@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (Medium) detected in srcvendor/nvi/2.2.1, openssh-portableV_9_6_P1 CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 Jan 22, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Jan 22, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 Jan 24, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Mar 4, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 Mar 4, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Mar 4, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 Mar 13, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Mar 14, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 Mar 20, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Mar 20, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 Mar 30, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Mar 30, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 Mar 31, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mandoc/dist/1.14.6, srcvendor/mandoc/dist/1.14.6 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Mar 31, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, freebsd-srcrelease/13.3.0 Mar 31, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, srcvendor/mport/2.6.1 Apr 3, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, srcvendor/mport/2.6.1 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Apr 7, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, freebsd-srcrelease/13.3.0 Apr 9, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Apr 9, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, freebsd-srcrelease/13.3.0 Apr 9, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in srcvendor/mport/2.6.1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, openssh-portableV_9_7_P1 Apr 11, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, openssh-portableV_9_7_P1 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 Apr 11, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, openssh-portableV_9_7_P1 Apr 12, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, openssh-portableV_9_7_P1 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 Apr 12, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Apr 14, 2024
Copy link
Contributor Author

✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.

@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 - autoclosed Apr 21, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 - autoclosed CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 Apr 26, 2024
Copy link
Contributor Author

ℹ️ This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.

@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Apr 26, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 Apr 27, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Apr 27, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 May 3, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 May 3, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 - autoclosed May 9, 2024
Copy link
Contributor Author

✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.

@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 - autoclosed CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 May 19, 2024
Copy link
Contributor Author

ℹ️ This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.

@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 May 19, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 May 22, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 May 22, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 May 22, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 May 22, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 Jun 6, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Jun 6, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 Jun 9, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Jun 9, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 Jun 10, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in openssh-portableV_9_7_P1, freebsd-srcrelease/13.3.0 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Jun 12, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 CVE-2023-51767 (High) detected in src3.1.5, src3.1.5 Jun 15, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2023-51767 (High) detected in src3.1.5, src3.1.5 CVE-2023-51767 (High) detected in src3.1.3, src3.1.3 Jun 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

1 participant