Back

MEDIUM

openssh: Unauthorized local access to host keys on platforms where ssh-rand-helper used

Published Feb 3, 2014

Description

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of openssh as shipped with Red Hat Enterprise Linux 4, 5, and 6, as they use a built-in entropy pool to generate and retrieve entropy information when performing host-based authentication.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 3, 2014
Updated May 29, 2026
Reserved Nov 4, 2011
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 5, 2011