[Bug 230029] [NEW] ssh-vulnkey overlooks keys which have options in authorized_keys

Matt Zimmerman mdz at ubuntu.com
Tue May 13 18:14:33 BST 2008


Public bug reported:

ssh-vulnkey failed to alert on this key:

command="dovecot -c ~/mail/dovecot.conf --exec-mail imap",no-pty,no-
agent-forwarding,no-X11-forwarding,no-port-forwarding ssh-rsa
AAAAB3NzaC1yc2EAAAABIwAAAQEAqDA3EME8AgthQ7rnEhNSlmJmsdN7D0H4ImRvA6L9U9DkpOK4WqRksHfqO1YXFc9tgd2krKbfLBpmQuGSudRwDob42TVCgFo/afPgnEkgA6TAvRFJW5D6iZrOxQJH4reps6GPGr8MFhxKMAgJcj+0nYIDw0xhqhL/yR4Cl6QbBNC1r4Gp+eq4pvlg+aN2QRePxTdJf/cKNgXPMUc6dzrzQxhsyD5XK/30AQEd3SpEjQXzHm88I/dThVxknBnKizculI2c9buhPEKVpcemOkyoTFegmtKhlhjVio9DfzVbwMQ+Q+J9RpuBgRp6tPgikYPmNB5dsq5sNYDgdGX47ybWHQ==
mdz at potpal

though it is a weak one.  Removing the options enabled it to correctly
detect the key.

** Affects: openssh (Ubuntu)
     Importance: Undecided
         Status: New

-- 
ssh-vulnkey overlooks keys which have options in authorized_keys
https://bugs.launchpad.net/bugs/230029
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to openssh in ubuntu.



More information about the Ubuntu-server-bugs mailing list