Bug 1394

Summary: SCP used to overwrite key
Product: Portable OpenSSH Reporter: Joel <FoxDie7987>
Component: scpAssignee: Assigned to nobody <unassigned-bugs>
Status: CLOSED INVALID    
Severity: normal    
Priority: P2    
Version: 4.7p1   
Hardware: Other   
OS: Linux   

Description Joel 2007-11-27 23:09:09 AEDT
Hi, I don't know if this is a bug, but I have been searching in Google and the project's web, and I haven't found anything. I think that I haven't found anything because my bad English, but I put this here because I don't know what to do. I'm using an up to date Gentoo 2007.0, with openssh 4.7-r1 (marked as stable), and ssh with a key with passphrase. I have found that if I do an "scp key.pub user@hostname:/home/user/.ssh/authorized_keys", scp ask me for the user password and not for the key, so if I know the password of the user, I can overwrite the key and get the control of that machine. I don't know if this is a problem of my configuration (same as Gentoo default, but without permission of root and password login), a patched version of the Gentoo team, or of the original version. Thanks, and sorry if I'm wrong and I have made that the person who reads this wastes his time. Sorry also for my mistakes, as I mentioned above, I have a bad English but I'm trying to improve it.
Comment 1 Damien Miller 2008-04-04 10:01:26 AEDT
Close resolved bugs after release.