CVE

Id
3973  
CVE No.
CVE-2001-1169  
Status
Candidate  
Description
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.  
Phase
Proposed (20020315)  
Votes
ACCEPT(1) Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | REVIEWING(1) Frech  
Comments