CVE-2001-1380

OpenSSH < 2.9.9 - Unauthenticated Remote Login Bypass via Authorized Keys 'from' Option

Title source: llm
STIX 2.1

Description

OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.

References (10)

Core 10
Core References
Various Sources vendor-advisory x_refsource_immunix
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3369
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2001-114.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=100154541809940&w=2
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000431
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/905795
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/m-010.shtml
Various Sources vendor-advisory x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-081.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/642
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7179

Scores

EPSS 0.0333
EPSS Percentile 87.4%

Details

Status published
Products (1)
openbsd/openssh < 2.9.9
Published Oct 18, 2001
Tracked Since Feb 18, 2026