Security Advisory
CVE-2011-4327
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.