PT-2007-2287 · Pam Ssh · Pam Ssh

Published

2007-02-08

·

Updated

2011-03-08

·

CVE-2007-0844

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: pam ssh versions prior to 1.92
Description: The issue allows remote attackers to bypass authentication restrictions by using private encryption keys that require a blank passphrase, even when the allow blank passphrase option is disabled. This is possible by entering a non-blank passphrase in the auth via key function.
Recommendations: For versions prior to 1.92, update to version 1.92 or later to resolve the issue. As a temporary workaround, consider enabling the allow blank passphrase option to restrict the use of private encryption keys with blank passphrases.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0844

Affected Products

Pam Ssh