The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite. NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssh | Jul 30, 2024 | Jan 27, 2012 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Jan 27, 2012 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 5.7 | Dec 5, 2012 | Jan 27, 2012 |
| Oracle Solaris | — | Upgrade network/ssh to version 0.5.11-0.175.1.7.0.4.2 on Solaris 11.1Upgrade service/network/ssh to version 0.5.11-0.175.1.7.0.4.2 on Solaris 11.1Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2 | May 29, 2017 | Jan 27, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 26, 2012 |
| Suse | — | Upgrade openssh-openssl1-helpersUpgrade openssh-openssl1Upgrade openssh-fipsUpgrade openssh-askpassUpgrade openssh | Dec 12, 2013 | Jul 11, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub