PT-2005-3554 · Openssh+2 · Openssh+2
Cynthia Mclain
+4
·
Publicado
2005-08-23
·
Atualizado
2024-07-08
·
CVE-2005-2666
CVSS v2.0
1.2
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions prior to 4.0
Description
The issue allows an attacker that has compromised an SSH user's account to more easily generate a list of additional targets that are more likely to have the same password or key. This is because hostnames, IP addresses, and keys are stored in plaintext in the known hosts file.
Recommendations
For OpenSSH versions prior to 4.0, update to version 4.0 or later to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Openssh
Red Hat