CVE Vulnerabilities

CVE-2008-2285

Published: May 18, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.

Affected Software

Name Vendor Start Version End Version
Linux Ubuntu 7.04 (including) 7.04 (including)
Linux Ubuntu 7.10 (including) 7.10 (including)
Linux Ubuntu 8.04 (including) 8.04 (including)
Openssh Ubuntu dapper *
Openssh Ubuntu feisty *
Openssh Ubuntu gutsy *
Openssh Ubuntu hardy *

References