CVE-2005-2666
Summary
| CVE | CVE-2005-2666 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-08-23 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a list of additional targets that are more likely to have the same password or key. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:H/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openbsd | Openssh | 3.0 | All | All | All |
| Application | Openbsd | Openssh | 3.0.1 | All | All | All |
| Application | Openbsd | Openssh | 3.0.1p1 | All | All | All |
| Application | Openbsd | Openssh | 3.0.2 | All | All | All |
| Application | Openbsd | Openssh | 3.0.2p1 | All | All | All |
| Application | Openbsd | Openssh | 3.0p1 | All | All | All |
| Application | Openbsd | Openssh | 3.1 | All | All | All |
| Application | Openbsd | Openssh | 3.1p1 | All | All | All |
| Application | Openbsd | Openssh | 3.2 | All | All | All |
| Application | Openbsd | Openssh | 3.2.2p1 | All | All | All |
| Application | Openbsd | Openssh | 3.2.3p1 | All | All | All |
| Application | Openbsd | Openssh | 3.3 | All | All | All |
| Application | Openbsd | Openssh | 3.3p1 | All | All | All |
| Application | Openbsd | Openssh | 3.4 | All | All | All |
| Application | Openbsd | Openssh | 3.4p1 | All | All | All |
| Application | Openbsd | Openssh | 3.5 | All | All | All |
| Application | Openbsd | Openssh | 3.5p1 | All | All | All |
| Application | Openbsd | Openssh | 3.6 | All | All | All |
| Application | Openbsd | Openssh | 3.6.1 | All | All | All |
| Application | Openbsd | Openssh | 3.6.1p1 | All | All | All |
| Application | Openbsd | Openssh | 3.6.1p2 | All | All | All |
| Application | Openbsd | Openssh | 3.7 | All | All | All |
| Application | Openbsd | Openssh | 3.7.1 | All | All | All |
| Application | Openbsd | Openssh | 3.7.1p2 | All | All | All |
| Application | Openbsd | Openssh | 3.8 | All | All | All |
| Application | Openbsd | Openssh | 3.8.1 | All | All | All |
| Application | Openbsd | Openssh | 3.8.1p1 | All | All | All |
| Application | Openbsd | Openssh | 3.9 | All | All | All |
| Application | Openbsd | Openssh | 3.9.1 | All | All | All |
| Application | Openbsd | Openssh | 3.9.1p1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Secunia - Advisories - SCO OpenServer update for OpenSSH | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | |
| NMS @ MIT CSAIL: Secure Shell Shock | af854a3a-2127-422b-91ae-364da2661108 | nms.csail.mit.edu | Patch |
| Page not found | eWEEK | af854a3a-2127-422b-91ae-364da2661108 | www.eweek.com | |
| Red Hat Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Page not found | eWEEK | MITRE | www.eweek.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2006-09-20 | Joshua Bressers | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162681 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/ |
There are currently no legacy QID mappings associated with this CVE.