First published: Wed Jul 05 2000(Updated: )
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ssh Ssh | =1.2.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.