CVE-2001-1380Openssh vulnerability

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
3.3%
top 12.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 18
Latest updateApr 30

Description

OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDopenbsd/openssh2.9.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-35mq-8mc3-vcm8: OpenSSH before 22022-04-30
CVEList
CVE-2001-1380: OpenSSH before 22003-04-02

📋Vendor Advisories

1
Red Hat
security flaw2001-09-26

💬Community

1
Bugzilla
CVE-2001-1380 security flaw2018-08-16
CVE-2001-1380 — Openbsd Openssh vulnerability | cvebase