Release date:
Updated on: 2012-04-26
Affected Systems:
Debian openssh-server. 5p1-6 + squeeze1
AVAYA 96x1 IP mobile phone 6.2
AVAYA 96x1 IP Phone 6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53247
Cve id: CVE-2012-0726, CVE-2012-0743
The openssh-server package provides sshd servers.
In OpenSSH versions earlier than 5.7, The auth_parse_options function in its sshd auth-options.c provides debugging information that contains the authorized_keys command option, there is an information leakage vulnerability in implementation, attackers can obtain sensitive information after successful exploitation.
<* Source: vendor
Link: https://downloads.avaya.com/css/P8/documents/100161262
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Debian
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.debian.org/security/