SSH客户端盗用证书账户访问漏洞

漏洞信息详情

SSH客户端盗用证书账户访问漏洞

漏洞简介

来自SSH客户端的盗用证书借助ssh-agent程序,其他本地用户可以访问属于ssh-agent用户的远程账户。

漏洞公告

参考网址

Vulnerable software and versionsConfiguration 1OR* cpe:/a:ssh:ssh:1.2.0* cpe:/a:ssh:ssh:1.2.1* cpe:/a:ssh:ssh:1.2.10* cpe:/a:ssh:ssh:1.2.11* cpe:/a:ssh:ssh:1.2.12* cpe:/a:ssh:ssh:1.2.13* cpe:/a:ssh:ssh:1.2.14* cpe:/a:ssh:ssh:1.2.2* cpe:/a:ssh:ssh:1.2.3* cpe:/a:ssh:ssh:1.2.4* cpe:/a:ssh:ssh:1.2.5* cpe:/a:ssh:ssh:1.2.6* cpe:/a:ssh:ssh:1.2.7* cpe:/a:ssh:ssh:1.2.8* cpe:/a:ssh:ssh:1.2.9* Denotes Vulnerable Software* Changes related to vulnerability configurations

Technical DetailsVulnerability Type (View All)
CVE Standard Vulnerability Entry:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0013

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享