PT-2011-2432 · Openssh+1 · Openssh+1
Mateusz Kocielski
·
Publicado
2011-02-10
·
Atualizado
2026-05-29
·
CVE-2011-0539
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions 5.6 through 5.7
Description
The issue is related to the key certify function in OpenSSH, specifically when generating legacy certificates using the -t command-line option in ssh-keygen. This function does not initialize the nonce field, which could allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.
Recommendations
For OpenSSH versions 5.6 through 5.7, consider disabling the use of the -t command-line option in ssh-keygen until a patch is available. As a temporary workaround, restrict access to the key certify function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Openssh