PT-2007-2287 · Pam Ssh · Pam Ssh
Published
2007-02-08
·
Updated
2011-03-08
·
CVE-2007-0844
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
pam ssh versions prior to 1.92
Description:
The issue allows remote attackers to bypass authentication restrictions by using private encryption keys that require a blank passphrase, even when the allow blank passphrase option is disabled. This is possible by entering a non-blank passphrase in the
auth via key function.Recommendations:
For versions prior to 1.92, update to version 1.92 or later to resolve the issue. As a temporary workaround, consider enabling the allow blank passphrase option to restrict the use of private encryption keys with blank passphrases.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pam Ssh