Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
BID:47691
Info
Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
| Bugtraq ID: | 47691 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 03 2011 12:00AM |
| Updated: | Jul 07 2011 04:30PM |
| Credit: | Tomas Mraz |
| Vulnerable: |
Pardus Linux 2009 0 OpenSSH OpenSSH 4.2 OpenSSH OpenSSH 4.1 p1 OpenSSH OpenSSH 4.1 OpenSSH OpenSSH 4.0 p1 OpenSSH OpenSSH 4.0 OpenSSH OpenSSH 3.9 p1 OpenSSH OpenSSH 3.8.1 p1 OpenSSH OpenSSH 3.8 p1 OpenSSH OpenSSH 3.7.2 p1 OpenSSH OpenSSH 3.7.1 p2 OpenSSH OpenSSH 3.7.1 p1 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 p2 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1-7 OpenSSH OpenSSH 3.4 p1-6 OpenSSH OpenSSH 3.4 p1-5 OpenSSH OpenSSH 3.4 p1-4 OpenSSH OpenSSH 3.4 p1-3 OpenSSH OpenSSH 3.4 p1-2 OpenSSH OpenSSH 3.4 p1-1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 5.8 OpenSSH OpenSSH 5.7 OpenSSH OpenSSH 5.6 OpenSSH OpenSSH 5.5 OpenSSH OpenSSH 5.4 OpenSSH OpenSSH 5.3 OpenSSH OpenSSH 5.2p1 OpenSSH OpenSSH 5.2 OpenSSH OpenSSH 5.1 OpenSSH OpenSSH 5.0 OpenSSH OpenSSH 4.9 OpenSSH OpenSSH 4.8 OpenSSH OpenSSH 4.7p1 OpenSSH OpenSSH 4.7 OpenSSH OpenSSH 4.6p1 OpenSSH OpenSSH 4.6 OpenSSH OpenSSH 4.5 OpenSSH OpenSSH 4.4.p1 OpenSSH OpenSSH 4.4 OpenSSH OpenSSH 4.3p2 OpenSSH OpenSSH 4.3p1 OpenSSH OpenSSH 4.2p1 |
| Not Vulnerable: |
OpenSSH OpenSSH 5.8 p2 |
Discussion
Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
Portable OpenSSH is prone to a local unauthorized-access vulnerability.
Local attackers can exploit this issue to gain access to host keys on the affected computer.
Portable OpenSSH is prone to a local unauthorized-access vulnerability.
Local attackers can exploit this issue to gain access to host keys on the affected computer.
Exploit / POC
Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
References:
References:
- OpenSSH Homepage (OpenSSH)
- OpenSSH Security Advisory: portable-keysign-rand-helper.adv (OpenSSH)