{"id":"CVE-2012-0814","details":"The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite.  NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory.","modified":"2026-04-10T03:42:12.102747Z","published":"2012-01-27T19:55:01Z","references":[{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657445"},{"type":"WEB","url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2012/01/26/15"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2012/01/26/16"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2012/01/27/1"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2012/01/27/4"},{"type":"WEB","url":"http://osvdb.org/78706"},{"type":"WEB","url":"http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c"},{"type":"WEB","url":"http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth-options.c.diff?r1=1.53%3Br2=1.54"},{"type":"WEB","url":"http://www.securityfocus.com/bid/51702"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72756"}],"schema_version":"1.7.5"}