{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2025-10-10T02:38:31Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/document/package-openssh-dev","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/openssh/package-openssh-dev/openssh/UNIHASH/document/package-openssh-dev"}],"name":"package-openssh-dev","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev","creationInfo":"_:CreationInfo0","description":"Secure rlogin/rsh/rcp/telnet replacement (OpenSSH) Ssh (Secure Shell) is a program for logging into a remote machine and for executing commands on a remote machine.  This package contains symbolic links, header files, and related items necessary for software development.","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/package/openssh-dev"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:openssh:10.2p1:*:*:*:*:*:*:*"}],"name":"openssh-dev","summary":"A suite of security-related network utilities based on the SSH protocol including the ssh client and sshd server - Development files","software_primaryPurpose":"install","software_homePage":"http://www.openssh.com/","software_packageVersion":"10.2p1"},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/1475869e389fd8137cccd4cd3d3189d8","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/relationship/1475869e389fd8137cccd4cd3d3189d8"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/license/3_27_0/BSD-2-Clause_AND_BSD-3-Clause_AND_ISC_AND_MIT"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/1ea8c13e0fbd430b4cfa322617429bef","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/relationship/1ea8c13e0fbd430b4cfa322617429bef"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2007-2768","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2008-3844","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2014-9278","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2023-51767"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/8ce7f94cc79a43782b6c11624b02ac9f","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/relationship/8ce7f94cc79a43782b6c11624b02ac9f"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev"],"scope":"build"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/057fc60848f1e970e36198b8abaebcc8","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/vex-not-affected/057fc60848f1e970e36198b8abaebcc8"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2023-51767","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev"],"security_vexVersion":"1.0.0","security_impactStatement":"It was demonstrated on modified sshd and does not exist in upstream openssh https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/5104ffb79175c144984200366d52263f","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/vex-not-affected/5104ffb79175c144984200366d52263f"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2008-3844","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev"],"security_vexVersion":"1.0.0","security_impactStatement":"Only applies to some distributed RHEL binaries.","security_justificationType":"vulnerableCodeNotPresent"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/56b9f2dd1fbe82c7efdbffa4114d8636","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/vex-not-affected/56b9f2dd1fbe82c7efdbffa4114d8636"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2007-2768","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev"],"security_vexVersion":"1.0.0","security_impactStatement":"This CVE is specific to OpenSSH with the pam opie which we don't build/use here.","security_justificationType":"vulnerableCodeNotPresent"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/ac404df79bbfce39ce92cd7e05238cc7","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/2717c8ebd7500e9d2a482415826b214141a8899706bcd4056bcf2491c23dbc8a/openssh/UNIHASH/vex-not-affected/ac404df79bbfce39ce92cd7e05238cc7"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2014-9278","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-dev"],"security_vexVersion":"1.0.0","security_impactStatement":"This CVE is specific to OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment","security_justificationType":"vulnerableCodeNotPresent"}]}