ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2001-01/0262.html | Exploit Patch Vendor Advisory |
http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html | Exploit Vendor Advisory |
http://www.securityfocus.com/bid/2222 | Exploit Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5963 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2001-06-01 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2001-0259
Mitre link : CVE-2001-0259
JSON object : View
CWE
Products Affected
ssh
- ssh