CVE-2005-2146
Summary
| CVE | CVE-2005-2146 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-07-05 04:00:00 UTC |
| Updated | 2008-09-05 20:51:00 UTC |
| Description | SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ssh | Tectia Server | 4.3.1 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page Not Found. Sorry about that! | CONFIRM | www.ssh.com | Patch, Vendor Advisory |
| Secunia - Advisories - SSH Tectia Server Insecure Private Key Permissions | SECUNIA | secunia.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.