PT-2007-2287 · Pam Ssh · Pam Ssh
Publicado
2007-02-08
·
Atualizado
2011-03-08
·
CVE-2007-0844
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
pam ssh versions prior to 1.92
Description:
The issue allows remote attackers to bypass authentication restrictions by using private encryption keys that require a blank passphrase, even when the allow blank passphrase option is disabled. This is possible by entering a non-blank passphrase in the
auth via key function.Recommendations:
For versions prior to 1.92, update to version 1.92 or later to resolve the issue. As a temporary workaround, consider enabling the allow blank passphrase option to restrict the use of private encryption keys with blank passphrases.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pam Ssh