[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2001-0259Date: (C)2001-06-02   (M)2023-12-22


ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.6
Exploit Score: 3.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://archives.neohapsis.com/archives/bugtraq/2001-01/0262.html
BID-2222
http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html
ssh-rpc-private-key

CPE    4
cpe:/a:ssh:ssh:1.2.29
cpe:/a:ssh:ssh:1.2.28
cpe:/a:ssh:ssh:1.2.27
cpe:/a:ssh:ssh:1.2.30
...

© SecPod Technologies