PT-2012-1159 · Openssh+2 · Openssh+2

·

CVE-2012-0814

·

Publicado

2012-01-27

·

Atualizado

2026-05-22

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 5.7 OpenSSH versions prior to 6.6 p1-r1
Description The issue allows remote authenticated users to obtain potentially sensitive information by reading debug messages containing authorized keys command options. This can cross privilege boundaries, as a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized keys file in its own home directory. Multiple vulnerabilities in the OpenSSH package can lead to violations of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For OpenSSH versions prior to 5.7, update to version 5.7 or later to resolve the issue. For OpenSSH versions prior to 6.6 p1-r1, update to version 6.6 p1-r1 or later to resolve the issue. As a temporary workaround, consider disabling the auth parse options function until a patch is available. Restrict access to sensitive information and authorized keys files to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-09678
CVE-2012-0814

Produtos afetados

Alt Linux
Openssh
Suse