CVE-2000-0575
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Affected
- ssh/ssh
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=96256265914116&w=2
- http://www.securityfocus.com/bid/1426Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4903
- http://marc.info/?l=bugtraq&m=96256265914116&w=2
- http://www.securityfocus.com/bid/1426Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4903
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.