High severity7.5NVD Advisory· Published Feb 10, 2011· Updated Jun 16, 2026
CVE-2011-0539
CVE-2011-0539
Description
The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 5.6 through 5.7
Patches
Vulnerability mechanics
References
10- www.openssh.com/txt/legacy-cert.advnvdPatchVendor Advisory
- secunia.com/advisories/43181nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0284nvdVendor Advisory
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvd
- kb.juniper.net/InfoCenter/indexnvd
- secunia.com/advisories/44269nvd
- www.openwall.com/lists/oss-security/2011/02/04/2nvd
- www.securityfocus.com/bid/46155nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/65163nvd
News mentions
0No linked articles in our index yet.