CVE-2012-0814

Source
https://nvd.nist.gov/vuln/detail/CVE-2012-0814
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2012-0814.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2012-0814
Downstream
Published
2012-01-27T19:55:01Z
Modified
2025-08-09T20:01:27Z
Summary
[none]
Details

The authparseoptions function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorizedkeys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite. NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorizedkeys file in its own home directory.

References

Affected packages