CVE Vulnerabilities

CVE-2011-4190

Published: Jun 08, 2018 | Modified: Nov 07, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).

Affected Software

Name Vendor Start Version End Version
Suse_linux_enterprise_desktop Suse 11-sp1 (including) 11-sp1 (including)
Suse_linux_enterprise_server Suse 11-sp1 (including) 11-sp1 (including)
Suse_linux_enterprise_server Suse 11.0-sp1 (including) 11.0-sp1 (including)

References