CVE-2008-2285

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
18/05/2008
Last modified:
08/08/2017

Description

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ubuntu:linux:7.04:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:linux:7.10:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:linux:8.04:*:*:*:*:*:*:*