Modify ↓
Ticket #588 (closed defect: fixed)
Insecure tempfile creation in SSHBase
Reported by: | [email protected]… | Owned by: | desai |
---|---|---|---|
Priority: | blocker | Milestone: | Bcfg2 0.9.6 Release |
Component: | bcfg2-server | Version: | |
Keywords: | security | Cc: |
Description
Hi,
The tempfile names used by SSHBase are predictable. For hosts witch keys not yet generated, a local attacker can choose the keys for the host.
The patch included fix this problem.
Attachments
Change History
comment:1 Changed 15 years ago by desai
- Status changed from new to closed
- Resolution set to fixed
- Milestone set to Bcfg2 0.9.6 Release
Committed in [9ef9c703159404dba311e18624d2fdd5fb399020] (SVN r4854). Thanks for the patch.
Note: See
TracTickets for help on using
tickets.