VDB

DEBIAN-CVE-2011-0539

DEBIAN-CVE-2011-0539 PUBLISHED CVSS 7.5 HIGH

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:12openssh0, 0, 0
Debian:11openssh0, 0, 0
Debian:14openssh0, 0, 0
Debian:13openssh0, 0, 0

Timeline

  • Feb 10, 2011 CVE Published
  • Aug 4, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›