LWN.net Logo

lsh-utils: local file descriptor leak

Package(s):lsh-utils CVE #(s):CVE-2006-0353
Created:January 26, 2006 Updated:February 1, 2006
Description: The lshd SSH2 protocol server has a file descriptor leak. User shells started by lshd can access randomness generator file descriptors, allowing the server seed file to be truncated. A denial of service is possible, and session keys may become vulnerable to cracking.
Alerts:
Debian DSA-956-1 2006-01-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds