First published: Sun May 18 2008(Updated: )
The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu BusyBox Static | =7.04 | |
Ubuntu BusyBox Static | =8.04 | |
Ubuntu BusyBox Static | =7.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2285 is classified as a moderate severity vulnerability.
CVE-2008-2285 affects the ssh-vulnkey tool by not recognizing authorized_keys lines with options, potentially enabling key guessing attacks.
CVE-2008-2285 affects Ubuntu Linux versions 7.04, 7.10, and 8.04 LTS.
To fix CVE-2008-2285, upgrade to a supported version of Ubuntu where the vulnerability has been patched.
The vulnerability can be exploited by attackers leveraging CVE-2008-0166 to compromise systems using weak or guessed SSH keys.