Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4327

Опубликовано: 05 мая 2011
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

Отчет

Not vulnerable. This issue did not affect the versions of openssh as shipped with Red Hat Enterprise Linux 4, 5, and 6, as they use a built-in entropy pool to generate and retrieve entropy information when performing host-based authentication.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4opensshNot affected
Red Hat Enterprise Linux 5opensshNot affected
Red Hat Enterprise Linux 6opensshNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=755640openssh: Unauthorized local access to host keys on platforms where ssh-rand-helper used

EPSS

Процентиль: 35%
0.00416
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 12 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

CVSS3: 5.5
nvd
больше 12 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

CVSS3: 5.5
debian
больше 12 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platfo ...

CVSS3: 5.5
github
больше 4 лет назад

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

EPSS

Процентиль: 35%
0.00416
Низкий

2.1 Low

CVSS2