CVE Vulnerabilities

CVE-2005-2666

Published: Aug 23, 2005 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.2 LOW
AV:L/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH users account to generate a list of additional targets that are more likely to have the same password or key.

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd 3.0 (including) 3.0 (including)
Openssh Openbsd 3.0.1 (including) 3.0.1 (including)
Openssh Openbsd 3.0.1p1 (including) 3.0.1p1 (including)
Openssh Openbsd 3.0.2 (including) 3.0.2 (including)
Openssh Openbsd 3.0.2p1 (including) 3.0.2p1 (including)
Openssh Openbsd 3.0p1 (including) 3.0p1 (including)
Openssh Openbsd 3.1 (including) 3.1 (including)
Openssh Openbsd 3.1p1 (including) 3.1p1 (including)
Openssh Openbsd 3.2 (including) 3.2 (including)
Openssh Openbsd 3.2.2p1 (including) 3.2.2p1 (including)
Openssh Openbsd 3.2.3p1 (including) 3.2.3p1 (including)
Openssh Openbsd 3.3 (including) 3.3 (including)
Openssh Openbsd 3.3p1 (including) 3.3p1 (including)
Openssh Openbsd 3.4 (including) 3.4 (including)
Openssh Openbsd 3.4p1 (including) 3.4p1 (including)
Openssh Openbsd 3.5 (including) 3.5 (including)
Openssh Openbsd 3.5p1 (including) 3.5p1 (including)
Openssh Openbsd 3.6 (including) 3.6 (including)
Openssh Openbsd 3.6.1 (including) 3.6.1 (including)
Openssh Openbsd 3.6.1p1 (including) 3.6.1p1 (including)
Openssh Openbsd 3.6.1p2 (including) 3.6.1p2 (including)
Openssh Openbsd 3.7 (including) 3.7 (including)
Openssh Openbsd 3.7.1 (including) 3.7.1 (including)
Openssh Openbsd 3.7.1p2 (including) 3.7.1p2 (including)
Openssh Openbsd 3.8 (including) 3.8 (including)
Openssh Openbsd 3.8.1 (including) 3.8.1 (including)
Openssh Openbsd 3.8.1p1 (including) 3.8.1p1 (including)
Openssh Openbsd 3.9 (including) 3.9 (including)
Openssh Openbsd 3.9.1 (including) 3.9.1 (including)
Openssh Openbsd 3.9.1p1 (including) 3.9.1p1 (including)
Red Hat Enterprise Linux 4 RedHat openssh-0:3.9p1-8.RHEL4.20 *
Openssh Ubuntu devel *

References