CVE-2008-2285: Medium severity ubuntu 22.04 lts vulnerability
The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorizedkeys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2285?
CVE-2008-2285 is classified as a moderate severity vulnerability.
How does CVE-2008-2285 affect authorized_keys?
CVE-2008-2285 affects the ssh-vulnkey tool by not recognizing authorized_keys lines with options, potentially enabling key guessing attacks.
Which Ubuntu versions are affected by CVE-2008-2285?
CVE-2008-2285 affects Ubuntu Linux versions 7.04, 7.10, and 8.04 LTS.
How do I fix CVE-2008-2285?
To fix CVE-2008-2285, upgrade to a supported version of Ubuntu where the vulnerability has been patched.
What is the potential exploit linked to CVE-2008-2285?
The vulnerability can be exploited by attackers leveraging CVE-2008-0166 to compromise systems using weak or guessed SSH keys.