CVE Database
/

CVE-2011-3588

Back to search

CVE-2011-3588

Published: Feb 15, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The SSH configuration in the Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, disables the StrictHostKeyChecking option, which allows man-in-the-middle attackers to spoof kdump servers, and obtain sensitive core information, by using an arbitrary SSH key.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2011:1532
vendor-advisory
x_refsource_REDHAT
RHSA-2012:0152
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now