{"id":"ECHO-3041-f7d2-3868","summary":"Upstream does not consider this a bug underlying in OpenSSH and does not\nintent to address it in OpenSSH. Additionally, this attack was not demonstrated\nagainst stock OpenSSH, and has never been demonstrated to be exploitable in a real\nsoftware configuration.\nhttps://security-tracker.debian.org/tracker/CVE-2023-51767\nhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059393\nhttps://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1\n","modified":"2026-09-15T00:57:40.965982339Z","published":"2025-08-29T01:37:38.151596Z","withdrawn":"2025-08-03T16:59:07.240Z","upstream":["CVE-2023-51767","GHSA-27q9-h529-q4g3"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2023-51767"}],"affected":[{"package":{"name":"openssh","ecosystem":"Echo","purl":"pkg:deb/echo/openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:9.2p1-2+deb12u6"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-3041-f7d2-3868.json"}}],"schema_version":"1.9.0"}