PT-1999-1667 · Red Hat · Red Hat

Published

1999-10-07

·

Updated

2016-10-18

·

CVE-1999-1346

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Red Hat Linux versions 6.1 and earlier
Description: The PAM configuration file for rlogin includes a less restrictive rule before a more restrictive one. This allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.
Recommendations: For Red Hat Linux versions 6.1 and earlier, consider reconfiguring the PAM settings to prioritize more restrictive rules over less restrictive ones to prevent unauthorized access via rlogin. As a temporary workaround, restrict access to the rlogin service until the PAM configuration can be updated.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1346

Affected Products

Red Hat