Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-4327

Опубликовано: 03 фев. 2014
Источник: debian
EPSS Низкий

Описание

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshnot-affectedpackage

Примечания

  • http://www.openssh.com/txt/portable-keysign-rand-helper.adv

EPSS

Процентиль: 35%
0.00416
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 12 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

redhat
больше 15 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

CVSS3: 5.5
nvd
больше 12 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

CVSS3: 5.5
github
больше 4 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

EPSS

Процентиль: 35%
0.00416
Низкий