ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.
No CVSS v3.1
No CVSS v3.0
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
AV:L/AC:L/Au:N/C:P/I:N/A:N
Vendors | Products |
---|---|
Openbsd |
|
Configuration 1 [-]
|
References
Link | Resource |
---|---|
http://www.openssh.com/txt/portable-keysign-rand-helper.adv | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=755640 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2014-02-03T02:00:00
Updated: 2014-02-03T02:57:00
Reserved: 2011-11-04T00:00:00
Link: CVE-2011-4327
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-02-03T03:55:03.550
Modified: 2014-02-21T18:12:30.890
Link: CVE-2011-4327
JSON object: View
Redhat Information
No data.
CWE