CVE-2011-4190: Missing verification of host key for kdump server
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2011-4190?
CVE-2011-4190 is a vulnerability in the kdump implementation that is specific to SUSE Linux Enterprise Server and SUSE Linux Enterprise Desktop.
What is the severity of CVE-2011-4190?
The severity of CVE-2011-4190 is medium, with a severity value of 5.3.
How does CVE-2011-4190 affect SUSE Linux Enterprise Server?
CVE-2011-4190 affects SUSE Linux Enterprise Server versions 11 and 11.0 SP1.
How does CVE-2011-4190 affect SUSE Linux Enterprise Desktop?
CVE-2011-4190 affects SUSE Linux Enterprise Desktop version 11 SP1.
Where can I find more information about CVE-2011-4190?
You can find more information about CVE-2011-4190 at the following links: 1. [SUSE Security Advisory](https://www.suse.com/security/cve/CVE-2011-4190/) 2. [SUSE Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=722440)