Information disclosure in OpenSSH - CVE-2011-4327
Published: February 3, 2014 / Updated: August 10, 2020
OpenSSH
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.