CVE-2001-1380: High severity OpenBSD OpenSSH vulnerability
OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorizedkeys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1380?
CVE-2001-1380 is classified as a high-severity vulnerability due to its potential to allow unauthorized remote access.
How do I fix CVE-2001-1380?
To fix CVE-2001-1380, upgrade OpenSSH to version 2.9.9 or later.
What are the potential risks associated with CVE-2001-1380?
The risks of CVE-2001-1380 include unauthorized access to systems that could lead to data breaches and compromised security.
What systems are affected by CVE-2001-1380?
CVE-2001-1380 affects OpenSSH versions prior to 2.9.9, specifically those using keypairs in the authorized_keys2 file.
Can CVE-2001-1380 be exploited remotely?
Yes, CVE-2001-1380 can be exploited remotely, allowing attackers to bypass restrictions on IP addresses.