Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

SSH Secure Shell/Tectia Server on Windows Host Identification Key Permission Vulnerability

SSH Secure Shell/Tectia Server on Windows platforms are prone to a vulnerability that could disclose private keys to other users of the computer. This is due to insecure default permissions on the file containing the private key.

A malicious user who obtains the host identification key could potentially use the key in attacks against clients.

SSH Secure Shell was re-branded Tectia Server as of Tectia Server release 4.0.







 

Privacy Statement
Copyright 2008, SecurityFocus