PT-1999-1667 · Red Hat · Red Hat
Published
1999-10-07
·
Updated
2016-10-18
·
CVE-1999-1346
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Red Hat Linux versions 6.1 and earlier
Description:
The PAM configuration file for rlogin includes a less restrictive rule before a more restrictive one. This allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.
Recommendations:
For Red Hat Linux versions 6.1 and earlier, consider reconfiguring the PAM settings to prioritize more restrictive rules over less restrictive ones to prevent unauthorized access via rlogin. As a temporary workaround, restrict access to the rlogin service until the PAM configuration can be updated.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat