5
CVSSv2

CVE-2008-2285

Published: 18/05/2008 Updated: 08/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote malicious users to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ubuntu linux 7.04

ubuntu linux 7.10

ubuntu linux 8.04

Vendor Advisories

Matt Zimmerman discovered that entries in ~/ssh/authorized_keys with options (such as “no-port-forwarding” or forced commands) were ignored by the new ssh-vulnkey tool introduced in OpenSSH (see USN-612-2) This could cause some compromised keys not to be listed in ssh-vulnkey’s output ...