Upstream information

CVE-2011-4327 at MITRE

Description

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

SUSE information

Overall state of this security issue: Ignore

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 2.1
Vector AV:L/AC:L/Au:N/C:P/I:N/A:N
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Note from the SUSE Security Team

SUSE Linux Enterprise does not include the ssh-rand-helper binary, so is not affected by this issue.

SUSE Bugzilla entry: 691400 [RESOLVED / INVALID]

No SUSE Security Announcements cross referenced.