oss-sec mailing list archives
Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
From: Peter Gutmann <pgut001 () cs auckland ac nz>
Date: Mon, 29 Sep 2025 03:57:52 +0000
Damien Miller <djm () mindrot org> writes:
The fact that someone filed this CVE based on your paper demonstrates that it is misleading.
Everyone gets that at some point. There was a discussion on another mailing list about it a while back, how do you respond to a CVE for a vulnerability that doesn't exist unless you modify the code or config in order to create it? The general feeling was that it's best just to grin and bear it, you're going to get them at some point no matter what you do. In particular, some obscure vuln that no-one will ever exploit only becomes publishable if you demonstrate it against a well-known project like OpenSSL, or OpenSSL, or OpenSSL, or OpenSSL, maybe GPG, or OpenSSL, and occasionally OpenSSH. But almost always OpenSSL. The only complication I've run into was when I was contacted by a user asking whether the problem in CVE xyz had been fixed. That was the first time I'd heard about it (the person who filed the CVE never bothered contacting me), and then I had to figure out how to explain to them that there was no fix because the vulnerability didn't exist unless you added it yourself. Peter.
Current thread:
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH, (continued)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Peter Gutmann (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Peter Gutmann (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour (Sep 27)
- Message not available
- Re: CVE-2023-51767: a bogus CVE in OpenSSH Damien Miller (Sep 24)
- Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Theo de Raadt (Sep 28)
- Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Adiletta, Andrew (Sep 28)
- Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Theo de Raadt (Sep 28)
- Message not available
- Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Damien Miller (Sep 28)
- Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Theo de Raadt (Sep 29)
- Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Peter Gutmann (Sep 29)
- Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Theo de Raadt (Sep 29)
