CVE-2011-4327

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

medium 5.5 CVSS 3.1
Published: Feb 3, 2014
Modified: May 29, 2026
Vendor: Openbsd
Product: Openssh
Versions: 1.2,1.2.1,1.2.2,1.2.3,1.2.27,1.3,1.5,1.5.7,1.5.8,2

Description

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

References

Related CVEs