CVE-2012-0814 (GCVE-0-2012-0814)

Vulnerability from cvelistv5 – Published: 2012-01-27 19:00 – Updated: 2026-05-22 10:28
VLAI
Summary
The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite. NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-05-22 10:26 UTC
CWE
  • n/a
  • CWE-532 - Insertion of Sensitive Information into Log File
Date Public
2012-01-26 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-06T18:38:14.970Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "51702",
            "tags": [
              "vdb-entry",
              "x_refsource_BID",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/51702"
          },
          {
            "name": "[oss-security] 20120127 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
            "tags": [
              "mailing-list",
              "x_refsource_MLIST",
              "x_transferred"
            ],
            "url": "http://openwall.com/lists/oss-security/2012/01/27/4"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
          },
          {
            "name": "[oss-security] 20120126 CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
            "tags": [
              "mailing-list",
              "x_refsource_MLIST",
              "x_transferred"
            ],
            "url": "http://openwall.com/lists/oss-security/2012/01/26/15"
          },
          {
            "name": "78706",
            "tags": [
              "vdb-entry",
              "x_refsource_OSVDB",
              "x_transferred"
            ],
            "url": "http://osvdb.org/78706"
          },
          {
            "name": "opensshserver-commands-info-disc(72756)",
            "tags": [
              "vdb-entry",
              "x_refsource_XF",
              "x_transferred"
            ],
            "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/72756"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657445"
          },
          {
            "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
            "tags": [
              "mailing-list",
              "x_refsource_MLIST",
              "x_transferred"
            ],
            "url": "http://openwall.com/lists/oss-security/2012/01/26/16"
          },
          {
            "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
            "tags": [
              "mailing-list",
              "x_refsource_MLIST",
              "x_transferred"
            ],
            "url": "http://openwall.com/lists/oss-security/2012/01/27/1"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c.diff?r1=1.53%3Br2=1.54"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "NONE",
              "baseScore": 6.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2012-0814",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-22T10:26:37.305731Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-532",
                "description": "CWE-532 Insertion of Sensitive Information into Log File",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-22T10:28:10.281Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "n/a",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ],
      "datePublic": "2012-01-26T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite.  NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "n/a",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2017-08-28T12:57:01.000Z",
        "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "shortName": "redhat"
      },
      "references": [
        {
          "name": "51702",
          "tags": [
            "vdb-entry",
            "x_refsource_BID"
          ],
          "url": "http://www.securityfocus.com/bid/51702"
        },
        {
          "name": "[oss-security] 20120127 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
          "tags": [
            "mailing-list",
            "x_refsource_MLIST"
          ],
          "url": "http://openwall.com/lists/oss-security/2012/01/27/4"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
        },
        {
          "name": "[oss-security] 20120126 CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
          "tags": [
            "mailing-list",
            "x_refsource_MLIST"
          ],
          "url": "http://openwall.com/lists/oss-security/2012/01/26/15"
        },
        {
          "name": "78706",
          "tags": [
            "vdb-entry",
            "x_refsource_OSVDB"
          ],
          "url": "http://osvdb.org/78706"
        },
        {
          "name": "opensshserver-commands-info-disc(72756)",
          "tags": [
            "vdb-entry",
            "x_refsource_XF"
          ],
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/72756"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657445"
        },
        {
          "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
          "tags": [
            "mailing-list",
            "x_refsource_MLIST"
          ],
          "url": "http://openwall.com/lists/oss-security/2012/01/26/16"
        },
        {
          "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
          "tags": [
            "mailing-list",
            "x_refsource_MLIST"
          ],
          "url": "http://openwall.com/lists/oss-security/2012/01/27/1"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c.diff?r1=1.53%3Br2=1.54"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
    "assignerShortName": "redhat",
    "cveId": "CVE-2012-0814",
    "datePublished": "2012-01-27T19:00:00.000Z",
    "dateReserved": "2012-01-19T00:00:00.000Z",
    "dateUpdated": "2026-05-22T10:28:10.281Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2012-0814",
      "date": "2026-10-02",
      "epss": "0.03566",
      "percentile": "0.88985"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "product": "n/a",
                "vendor": "n/a",
                "versions": [
                  {
                    "status": "affected",
                    "version": "n/a"
                  }
                ]
              }
            ],
            "source": "secalert@redhat.com"
          }
        ],
        "configurations": [
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "607877D1-B86A-4973-A5D7-D3D0247FC272",
                    "versionEndIncluding": "5.6",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "316C8534-9CE3-456C-A04E-5D2B789FBE31",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.2.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "7BEB67BB-A442-46C2-8BC1-BBEB009AC532",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.2.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "B6E307F1-C765-409C-835C-133026A5179C",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.2.3:*:*:*:*:*:*:*",
                    "matchCriteriaId": "CA997F5E-29FE-454A-9006-001D732CD4B1",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.2.27:*:*:*:*:*:*:*",
                    "matchCriteriaId": "114134F3-BDFD-465D-8317-82F9D6EFA5A7",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.3:*:*:*:*:*:*:*",
                    "matchCriteriaId": "DAB55300-F90D-45D3-88BC-5ADCEC366264",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.5:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F3EC5611-31B5-4253-B99A-E81C202768A0",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.5.7:*:*:*:*:*:*:*",
                    "matchCriteriaId": "43060323-1B51-45B4-BEB9-0E472896D8EA",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:1.5.8:*:*:*:*:*:*:*",
                    "matchCriteriaId": "5441C616-D127-42D9-88AA-0FC9AA16EB03",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "FE60A415-91E3-4819-A252-E86A32EC3018",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "EED5E506-9D2B-4CAF-8455-B9BE7696E49C",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.1.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "EE7CB94E-0479-4939-86F6-0B4BEDE2E739",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "78135400-BA1A-42AA-BE17-5588442BCF11",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.3:*:*:*:*:*:*:*",
                    "matchCriteriaId": "78F2EDC0-3189-4523-882B-9188C852F793",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.3.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "CDEF5203-9D6B-4431-BF0D-C81B1E250AEC",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.5:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E2991C07-5486-4590-A74E-46A379DD3339",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.5.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "4EB9BE06-0A36-4853-ADF4-9C1A1854278A",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.5.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "8FC57F38-6545-497B-B6DA-FCAF51755988",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.9:*:*:*:*:*:*:*",
                    "matchCriteriaId": "EC30FD61-10DA-4C9B-BCE8-AD75DCEB40BC",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.9.9:*:*:*:*:*:*:*",
                    "matchCriteriaId": "EC1DF4CE-E71C-4C10-9F82-B9ECDC94933F",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.9.9p2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "80C55B73-497D-4A22-9230-A4160BF97344",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.9p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "0238F009-4BBA-4E6B-9E2A-6045BA9BBE9C",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:2.9p2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "4B235167-9554-4431-88C5-9472DD36FCDE",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.0:*:*:*:*:*:*:*",
                    "matchCriteriaId": "580008AC-2667-4708-8F7E-D70416A460EE",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.0.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E05D8E86-EC01-4589-B372-4DEB7845C81F",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.0.1p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "764AD252-CA2F-4A87-BCAA-7747E8C410E0",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.0.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "CFFAA075-4277-4FD8-8A5A-867EEE1BA2F4",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.0.2p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "269BB9F7-55E5-4CB3-8429-C37C7132799F",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.0p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "C6E6F639-31A0-4026-B6D4-51BA79FB1D20",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "0211BCE3-0DED-40BA-8A21-1A97B91F71C7",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.1p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "B4EE9E4B-CABC-4EA2-9075-CC23CEB1B0A3",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "5AD7BB30-AC79-4153-852C-1053DCF4DE53",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.2.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F48519C6-0C28-49A5-94C7-EF3AA88E2667",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.2.2p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "9E188C66-C8F1-4C13-AAFF-7C83B2A884B8",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.2.3p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "9039BE91-AF0A-41E7-8F9F-15375890E120",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.3:*:*:*:*:*:*:*",
                    "matchCriteriaId": "08BCB2EA-DF9D-4853-805B-29FA6274E2B7",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.3p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "0F93417F-2498-4576-9F5D-B59F77D39669",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.4:*:*:*:*:*:*:*",
                    "matchCriteriaId": "AF3AB42C-B614-4746-99AD-E94140D91BF3",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.4p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "458167E5-9BC2-40BE-AC8A-9761A4F19494",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.5:*:*:*:*:*:*:*",
                    "matchCriteriaId": "3FB9B4C7-4235-4388-8E5D-E72ECCC37A7E",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.5p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "86ACA0ED-A3D0-48A7-B06F-13709AD23B55",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.6:*:*:*:*:*:*:*",
                    "matchCriteriaId": "0FEB9262-D05E-4610-9C79-3EDE44AC7C0B",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.6.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "8176879B-1875-4AC9-B15A-2ABCFCD04F88",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.6.1p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "FAA26A12-F96A-4025-BBCA-72B7A3B1E60C",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.6.1p2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "A02751E9-2D38-4495-9572-8D84D71D4773",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.7:*:*:*:*:*:*:*",
                    "matchCriteriaId": "7A36BEA2-DAE4-423C-8D85-0F6036351F98",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.7.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "80DC64F6-FE28-44BA-91D1-EC2DB11B2CFC",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.7.1p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "DF23EBA1-D3A9-413F-9E83-43A91492C031",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.7.1p2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "44CCF5CD-B434-4392-A79A-C1945D2AE30A",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.8:*:*:*:*:*:*:*",
                    "matchCriteriaId": "AEB456B8-9D8B-4985-858D-6A43FA5EE2E9",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.8.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "2BD4E0F6-4EEA-4EC7-83E7-FC6F7D2E7A3C",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.8.1p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "C35F4ABE-1B0C-4195-8F99-BF993A17882B",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.9:*:*:*:*:*:*:*",
                    "matchCriteriaId": "ADC7352D-2916-47F7-A256-F897D763DC9B",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.9.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "AEC3FC36-B246-4DCB-8984-228525D9A356",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:3.9.1p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "BC861000-37D8-4B0F-BFA0-57E9BE125B56",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.0:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E003AB3C-8DF3-4AE8-82A3-984F30E5599B",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.0p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "5EBE75FE-DDE2-43BA-80EF-15A6698EABC9",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "1FF67D77-02AC-4807-984D-C5AE9799F051",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.1p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "683B26F0-5EA2-455A-8948-27C100BBA3AC",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E5A75B23-2DD7-4EB2-BEAA-049FF4E51A14",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.2p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "7279E1EC-DEBC-4ACC-925D-06A7697C162F",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.3:*:*:*:*:*:*:*",
                    "matchCriteriaId": "7910598E-BEC1-4644-9DE4-D8BE505A4F9E",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.3p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "FB416D0C-6C86-450F-8917-D4B1BD82AB1E",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.3p2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "3640CCC9-EC4A-44A4-B747-7BAAAD3460C7",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.4:*:*:*:*:*:*:*",
                    "matchCriteriaId": "B2DD362E-9EA9-4E88-9A94-D7B471EB1FD4",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.4p1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E3094069-AC2E-43BD-8094-D48E2526DECC",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.5:*:*:*:*:*:*:*",
                    "matchCriteriaId": "9B72CFB3-39C7-469C-AA59-69F5B8993BF7",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.6:*:*:*:*:*:*:*",
                    "matchCriteriaId": "2A7154C4-8325-4495-92B1-B7897CD7303E",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.7:*:*:*:*:*:*:*",
                    "matchCriteriaId": "99BF4471-763B-485A-ABD5-C68AD0A14058",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.8:*:*:*:*:*:*:*",
                    "matchCriteriaId": "40B1B209-53B8-48DC-AFFC-BD69D5978A0B",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:4.9:*:*:*:*:*:*:*",
                    "matchCriteriaId": "7212E982-76F2-496C-9F08-EC4137F20804",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:5.0:*:*:*:*:*:*:*",
                    "matchCriteriaId": "52D13E08-7B08-44AA-9017-3EE3F6301E10",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:5.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "2FBC7FF1-01EE-40A1-8735-14360A371803",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:5.2:*:*:*:*:*:*:*",
                    "matchCriteriaId": "987527F8-8A42-4729-A329-4D2AC8AFD6E1",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:5.3:*:*:*:*:*:*:*",
                    "matchCriteriaId": "93910448-8D6F-4F7E-9C7F-959754ABA50D",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:5.4:*:*:*:*:*:*:*",
                    "matchCriteriaId": "3356FDFD-BEA5-45A5-A36B-D1153AFE6C23",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:openbsd:openssh:5.5:*:*:*:*:*:*:*",
                    "matchCriteriaId": "9394B8AD-AB22-4955-8774-C6BA2B56A260",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ]
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite.  NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory."
          },
          {
            "lang": "es",
            "value": "La funci\u00f3n auth_parse_options en auth-options.c en el demonio sshd de OpenSSH antes de v5.7 muestra mensajes de depuraci\u00f3n que contienen opciones del comando authorized_keys, lo que permite obtener informaci\u00f3n sensible a usuarios remotos autenticados mediante la lectura de estos mensajes. El problema queda demostrado con la cuenta de usuario compartida solicitada por Gitolite. NOTA: esto puede cruzar los l\u00edmites de los privilegios, porque una cuenta de usuario intencionalmente no tiene acceso a una \u0027shell\u0027 o al sistema de archivos, y por lo tanto no tienen forma de leer un archivo authorized_keys en su propio directorio."
          }
        ],
        "id": "CVE-2012-0814",
        "lastModified": "2026-06-16T23:38:18.700",
        "metrics": {
          "cvssMetricV2": [
            {
              "acInsufInfo": false,
              "baseSeverity": "LOW",
              "cvssData": {
                "accessComplexity": "MEDIUM",
                "accessVector": "NETWORK",
                "authentication": "SINGLE",
                "availabilityImpact": "NONE",
                "baseScore": 3.5,
                "confidentialityImpact": "PARTIAL",
                "integrityImpact": "NONE",
                "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
                "version": "2.0"
              },
              "exploitabilityScore": 6.8,
              "impactScore": 2.9,
              "obtainAllPrivilege": false,
              "obtainOtherPrivilege": false,
              "obtainUserPrivilege": false,
              "source": "nvd@nist.gov",
              "type": "Primary",
              "userInteractionRequired": false
            }
          ],
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "exploitabilityScore": 2.8,
              "impactScore": 3.6,
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ],
          "ssvcV203": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "ssvcData": {
                "id": "CVE-2012-0814",
                "options": [
                  {
                    "exploitation": "none"
                  },
                  {
                    "automatable": "no"
                  },
                  {
                    "technicalImpact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-22T10:26:37.305731Z",
                "version": "2.0.3"
              }
            }
          ]
        },
        "published": "2012-01-27T19:55:01.063",
        "references": [
          {
            "source": "secalert@redhat.com",
            "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657445"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://openwall.com/lists/oss-security/2012/01/26/15"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://openwall.com/lists/oss-security/2012/01/26/16"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://openwall.com/lists/oss-security/2012/01/27/1"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://openwall.com/lists/oss-security/2012/01/27/4"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://osvdb.org/78706"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c.diff?r1=1.53%3Br2=1.54"
          },
          {
            "source": "secalert@redhat.com",
            "url": "http://www.securityfocus.com/bid/51702"
          },
          {
            "source": "secalert@redhat.com",
            "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/72756"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657445"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://openwall.com/lists/oss-security/2012/01/26/15"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://openwall.com/lists/oss-security/2012/01/26/16"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://openwall.com/lists/oss-security/2012/01/27/1"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://openwall.com/lists/oss-security/2012/01/27/4"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://osvdb.org/78706"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c.diff?r1=1.53%3Br2=1.54"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "http://www.securityfocus.com/bid/51702"
          },
          {
            "source": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/72756"
          }
        ],
        "sourceIdentifier": "secalert@redhat.com",
        "vulnStatus": "Modified",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-255"
              }
            ],
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-532"
              }
            ],
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ]
      }
    },
    "redhat_vex": {
      "aggregate_severity": "Low",
      "current_release_date": "2025-11-21T12:54:17+00:00",
      "cve": "CVE-2012-0814",
      "id": "CVE-2012-0814",
      "initial_release_date": "2012-01-26T00:00:00+00:00",
      "product_status:known_affected": "7",
      "product_status:known_not_affected": "1",
      "source": "Red Hat CSAF VEX",
      "status": "final",
      "title": "openssh: forced command option information disclosure",
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2012/cve-2012-0814.json",
      "version": "3"
    },
    "vulnrichment": {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T18:38:14.970Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "51702",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/51702"
              },
              {
                "name": "[oss-security] 20120127 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://openwall.com/lists/oss-security/2012/01/27/4"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
              },
              {
                "name": "[oss-security] 20120126 CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://openwall.com/lists/oss-security/2012/01/26/15"
              },
              {
                "name": "78706",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://osvdb.org/78706"
              },
              {
                "name": "opensshserver-commands-info-disc(72756)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/72756"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657445"
              },
              {
                "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://openwall.com/lists/oss-security/2012/01/26/16"
              },
              {
                "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://openwall.com/lists/oss-security/2012/01/27/1"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c.diff?r1=1.53%3Br2=1.54"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2012-0814",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-22T10:26:37.305731Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-532",
                    "description": "CWE-532 Insertion of Sensitive Information into Log File",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-22T10:26:31.875Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2012-01-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite.  NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-08-28T12:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "51702",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/51702"
            },
            {
              "name": "[oss-security] 20120127 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://openwall.com/lists/oss-security/2012/01/27/4"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
            },
            {
              "name": "[oss-security] 20120126 CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://openwall.com/lists/oss-security/2012/01/26/15"
            },
            {
              "name": "78706",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://osvdb.org/78706"
            },
            {
              "name": "opensshserver-commands-info-disc(72756)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/72756"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657445"
            },
            {
              "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://openwall.com/lists/oss-security/2012/01/26/16"
            },
            {
              "name": "[oss-security] 20120126 Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://openwall.com/lists/oss-security/2012/01/27/1"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c.diff?r1=1.53%3Br2=1.54"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2012-0814",
        "datePublished": "2012-01-27T19:00:00.000Z",
        "dateReserved": "2012-01-19T00:00:00.000Z",
        "dateUpdated": "2026-05-22T10:28:10.281Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…