Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-2666
HistoryAug 23, 2005 - 12:00 a.m.

CVE-2005-2666

2005-08-2300:00:00
ubuntu.com
ubuntu.com
15

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

26.3%

SSH, as implemented in OpenSSH before 4.0 and possibly other
implementations, stores hostnames, IP addresses, and keys in plaintext in
the known_hosts file, which makes it easier for an attacker that has
compromised an SSH user’s account to generate a list of additional targets
that are more likely to have the same password or key.

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

26.3%