Back

HIGH

OpenSSH: legacy certificate generation information leak

Published Feb 10, 2011

Description

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of openssh as shipped with Red Hat Enterprise Linux 4, 5, or 6.

Metrics

Weaknesses (2)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 10, 2011
Updated May 29, 2026
Reserved Jan 20, 2011
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 4, 2011