LWN.net Logo

openssh: hash collision attacks

Package(s):openssh CVE #(s):CVE-2011-0539
Created:February 14, 2011 Updated:February 16, 2011
Description: From the Pardus advisory:

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

Alerts:
Pardus 2011-40 2011-02-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds