PT-2001-1770 · Openssh+1 · Openssh+1

Published

2001-07-27

·

Updated

2024-07-08

·

CVE-2001-0572

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenSSH (affected versions not specified)
Description: The SSH protocols 1 and 2 as implemented in OpenSSH have various weaknesses that can allow a remote attacker to obtain sensitive information via sniffing. This includes password lengths or ranges of lengths, which can simplify brute force password guessing, whether RSA or DSA authentication is being used, the number of authorized keys in RSA authentication, or the lengths of shell commands.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
CVE-2001-0572

Affected Products

Alt Linux
Openssh