PT-2007-2287 · Pam Ssh · Pam Ssh

Publicado

2007-02-08

·

Atualizado

2011-03-08

·

CVE-2007-0844

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: pam ssh versions prior to 1.92
Description: The issue allows remote attackers to bypass authentication restrictions by using private encryption keys that require a blank passphrase, even when the allow blank passphrase option is disabled. This is possible by entering a non-blank passphrase in the auth via key function.
Recommendations: For versions prior to 1.92, update to version 1.92 or later to resolve the issue. As a temporary workaround, consider enabling the allow blank passphrase option to restrict the use of private encryption keys with blank passphrases.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0844

Produtos afetados

Pam Ssh