CVE
- Id
- 13872
- CVE No.
- CVE-2005-2666
- Status
- Candidate
- Description
- SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user"s account to generate a list of additional targets that are more likely to have the same password or key.
- Phase
- Assigned (20050823)
- Votes
- None (candidate not yet proposed)
- Comments