CVE-2011-2390

Publication date 5 October 2011

Last updated 24 July 2024


Ubuntu priority

Description

The default value of "StrictHostKeyChecking=no" has been used for kdump/ mkdumprd openssh integration. A remote malicious kdump server could use this flaw to impersonate the intended, correct kdump server to obtain security sensitive information (kdump core files).

Status

Package Ubuntu Release Status
kexec-tools 11.10 oneiric Ignored end of life
11.04 natty Ignored end of life
10.10 maverick Ignored end of life
10.04 LTS lucid Ignored end of life
8.04 LTS hardy Ignored end of life


Access our resources on patching vulnerabilities