积极预防 及时发现
快速响应 力保恢复
带有Kerberos认证支持的SSH 1.2.27在一个正在登录的用户的当前目录创建的文件中存储Ke...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000575 CVE编号:CVE-2000-0575 安全级别:中 漏洞中文描述: 带有Kerberos认证支持的SSH 1.2.27在一个正在登录的用户的当前目录创建的文件中存储Kerberos 票证,这可能导致远程攻击者在主目录安装在NFS上时可以跟踪票证cache。 漏洞英文描述: SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on N 漏洞参考: 系统类型:其他 漏洞类型:其他