Description
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2000-0571 | SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T05:21:31.314Z
Reserved: 2000-07-19T00:00:00.000Z
Link: CVE-2000-0575
No data.
Status : Modified
Published: 2000-07-05T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2000-0575
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD