CVE-2006-0353: Infoleak
unixrandom.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0353?
CVE-2006-0353 is considered a medium severity vulnerability due to its potential for local denial of service and information disclosure.
How do I fix CVE-2006-0353?
To fix CVE-2006-0353, upgrade to a patched version of lsh that addresses this vulnerability.
What types of systems are affected by CVE-2006-0353?
CVE-2006-0353 specifically affects systems running lsh version 2.0.1.
Can CVE-2006-0353 lead to key cracking?
Yes, CVE-2006-0353 can lead to exposure of sensitive seed information that could be utilized to crack encryption keys.
What is the potential impact of exploiting CVE-2006-0353?
Exploitation of CVE-2006-0353 may result in a denial of service by preventing the server from starting or compromising the security of cryptographic keys.