|
|
| |
|
| |
openssh: hash collision attacks
| Package(s): | openssh |
CVE #(s): | CVE-2011-0539
|
| Created: | February 14, 2011 |
Updated: | February 16, 2011 |
| Description: |
From the Pardus advisory:
The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7,
when generating legacy certificates using the -t command-line option in
ssh-keygen, does not initialize the nonce field, which might allow
remote attackers to obtain sensitive stack memory contents or make it
easier to conduct hash collision attacks. |
| Alerts: |
|
( Log in to post comments)
|
|
|