PT-2003-1877 · Openssh+1 · Openssh+1

Petri Heinonen

·

Publicado

2003-09-25

·

Atualizado

2024-07-08

·

CVE-2003-0786

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSH versions 3.7.1 through 3.7.1p1
Description: The issue concerns the SSH1 PAM challenge response authentication mechanism in OpenSSH. When Privilege Separation is disabled, the authentication attempt result is not properly checked, potentially allowing remote attackers to gain privileges.
Recommendations: For OpenSSH versions 3.7.1 through 3.7.1p1, consider enabling Privilege Separation to mitigate the risk of exploitation. As a temporary workaround, restrict access to the SSH1 PAM challenge response authentication mechanism until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
CVE-2003-0786

Produtos afetados

Alt Linux
Openssh