{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2025-10-10T02:38:31Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/document/package-openssh-scp","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/openssh/package-openssh-scp/openssh/UNIHASH/document/package-openssh-scp"}],"name":"package-openssh-scp","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp","creationInfo":"_:CreationInfo1","description":"Secure rlogin/rsh/rcp/telnet replacement (OpenSSH) Ssh (Secure Shell) is a program for logging into a remote machine and for executing commands on a remote machine.","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/package/openssh-scp"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:openssh:10.2p1:*:*:*:*:*:*:*"}],"name":"openssh-scp","summary":"A suite of security-related network utilities based on the SSH protocol including the ssh client and sshd server","software_primaryPurpose":"install","software_homePage":"http://www.openssh.com/","software_packageVersion":"10.2p1"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp/file/1","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/package/openssh-scp/file/1"}],"name":"usr/bin/scp.openssh","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"e923ee4344c1fdd3f73bf5d4c9b1a73e38570045e9a0b34d945031b6f957c5f6"}]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/1c5a50e686df1d1bf2886401beab0f73","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/relationship/1c5a50e686df1d1bf2886401beab0f73"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/license/3_27_0/BSD-2-Clause_AND_BSD-3-Clause_AND_ISC_AND_MIT"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/676f918a010e087aef162702159586e3","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/relationship/676f918a010e087aef162702159586e3"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp","relationshipType":"contains","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp/file/1"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/840b5350a0d4eab024e789000aa33cbd","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/relationship/840b5350a0d4eab024e789000aa33cbd"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2007-2768","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2008-3844","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2014-9278","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2023-51767"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/984f2cf64c8dd5ba29e10279a9c3cdf0","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/relationship/984f2cf64c8dd5ba29e10279a9c3cdf0"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp"],"scope":"build"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/2d5cec752b0196ae4e09291e5b531ffe","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/vex-not-affected/2d5cec752b0196ae4e09291e5b531ffe"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2008-3844","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp"],"security_vexVersion":"1.0.0","security_impactStatement":"Only applies to some distributed RHEL binaries.","security_justificationType":"vulnerableCodeNotPresent"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/3526e3a29ae5a9569a257996aeb9d5f7","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/vex-not-affected/3526e3a29ae5a9569a257996aeb9d5f7"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2014-9278","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp"],"security_vexVersion":"1.0.0","security_impactStatement":"This CVE is specific to OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment","security_justificationType":"vulnerableCodeNotPresent"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/69eb666c4cd685f132f610464f2e187e","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/vex-not-affected/69eb666c4cd685f132f610464f2e187e"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2023-51767","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp"],"security_vexVersion":"1.0.0","security_impactStatement":"It was demonstrated on modified sshd and does not exist in upstream openssh https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/ec433a5117c045b3832941c96d157dba","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/51d49110cb4a87df8ad0f2c01464b9e85d5e234de2722368c3db96fe2d69fc6c/openssh/UNIHASH/vex-not-affected/ec433a5117c045b3832941c96d157dba"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2007-2768","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-scp"],"security_vexVersion":"1.0.0","security_impactStatement":"This CVE is specific to OpenSSH with the pam opie which we don't build/use here.","security_justificationType":"vulnerableCodeNotPresent"}]}