PT-2000-1509 · Openssh · Ssh
Published
2000-07-05
·
Updated
2017-10-10
·
CVE-2000-0575
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SSH version 1.2.27
Description
The issue concerns SSH with Kerberos authentication support, where Kerberos tickets are stored in a file created in the user's current directory. This could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.
Recommendations
For SSH version 1.2.27, consider restricting access to the home directory or avoiding the use of NFS for home directories to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ssh