Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-0557 | The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks. |
Fri, 29 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-457 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-29T20:34:45.288Z
Reserved: 2011-01-20T00:00:00.000Z
Link: CVE-2011-0539
Updated: 2024-08-06T21:58:25.891Z
Status : Modified
Published: 2011-02-10T18:00:57.660
Modified: 2026-06-16T23:27:35.500
Link: CVE-2011-0539
OpenCVE Enrichment
No data.
EUVD