PT-2001-1770 · Openssh+1 · Openssh+1
Published
2001-07-27
·
Updated
2024-07-08
·
CVE-2001-0572
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
OpenSSH (affected versions not specified)
Description:
The SSH protocols 1 and 2 as implemented in OpenSSH have various weaknesses that can allow a remote attacker to obtain sensitive information via sniffing. This includes password lengths or ranges of lengths, which can simplify brute force password guessing, whether RSA or DSA authentication is being used, the number of authorized keys in RSA authentication, or the lengths of shell commands.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Openssh