OpenSSH 'ssh-keysign.c' Local Information Disclosure Vulnerability
BID:65674
Info
OpenSSH 'ssh-keysign.c' Local Information Disclosure Vulnerability
| Bugtraq ID: | 65674 |
| Class: | Design Error |
| CVE: |
CVE-2011-4327 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 21 2011 12:00AM |
| Updated: | Nov 21 2011 12:00AM |
| Credit: | Tomas Mraz |
| Vulnerable: |
OpenBSD OpenSSH 3.8.1 p1 OpenBSD OpenSSH 3.0.2 p1 OpenBSD OpenSSH 3.0.2 OpenBSD OpenSSH 3.0.1 p1 OpenBSD OpenSSH 3.0.1 OpenBSD OpenSSH 3.0 p1 OpenBSD OpenSSH 3.0 OpenBSD OpenSSH 2.9 p2 OpenBSD OpenSSH 2.9 p1 OpenBSD OpenSSH 2.9 OpenBSD OpenSSH 2.5.2 p2 OpenBSD OpenSSH 2.5.2 OpenBSD OpenSSH 2.3.1 p1 OpenBSD OpenSSH 2.3.1 OpenBSD OpenSSH 2.1.1 p1 OpenBSD OpenSSH 2.1.1 OpenBSD OpenSSH 2.1 OpenBSD OpenSSH 1.2.3 OpenBSD OpenSSH 1.2 OpenBSD OpenSSH 5.8 OpenBSD OpenSSH 5.7 OpenBSD OpenSSH 5.6 OpenBSD OpenSSH 5.4 OpenBSD OpenSSH 5.2 OpenBSD OpenSSH 5.1 OpenBSD OpenSSH 4.9 OpenBSD OpenSSH 4.8 OpenBSD OpenSSH 4.7 OpenBSD OpenSSH 4.6 OpenBSD OpenSSH 4.5 OpenBSD OpenSSH 4.4 OpenBSD OpenSSH 4.3p1 OpenBSD OpenSSH 4.3 OpenBSD OpenSSH 4.2p1 OpenBSD OpenSSH 4.2 OpenBSD OpenSSH 4.1 OpenBSD OpenSSH 4.0 OpenBSD OpenSSH 3.9 p1 |
| Not Vulnerable: |
OpenBSD OpenSSH 5.8P2 |
Discussion
OpenSSH 'ssh-keysign.c' Local Information Disclosure Vulnerability
OpenSSH is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information. Information obtained may lead to further attacks.
Versions prior to OpenSSH 5.8p2 are vulnerable.
OpenSSH is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information. Information obtained may lead to further attacks.
Versions prior to OpenSSH 5.8p2 are vulnerable.
Exploit / POC
OpenSSH 'ssh-keysign.c' Local Information Disclosure Vulnerability
Attackers aquire local interactive access to an affected computer to exploit this issue.
Attackers aquire local interactive access to an affected computer to exploit this issue.
Solution / Fix
OpenSSH 'ssh-keysign.c' Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenSSH 'ssh-keysign.c' Local Information Disclosure Vulnerability
References:
References:
- Bug 755640 - (CVE-2011-4327) CVE-2011-4327 openssh: Unauthorized local access to (Red Hat Bugzilla)
- OpenSSH Homepage (OpenSSH)
- OpenSSH Security Advisory: portable-keysign-rand-helper.adv (OpenSSH)