PT-2007-4391 · Openbsd+1 · Openssh+1

Tomas Mraz

·

Published

2007-10-18

·

Updated

2017-10-11

·

CVE-2007-3102

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: OpenSSH version 4.3p2
Description: The issue allows remote attackers to write arbitrary characters to an audit log via a crafted username. This is due to an unspecified vulnerability in the linux audit record event function.
Recommendations: For OpenSSH version 4.3p2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3102
RHSA-2007:0540
RHSA-2007:0555
RHSA-2007:0703
RHSA-2007:0737
RHSA-2007_0540
RHSA-2007_0555
RHSA-2007_0703
RHSA-2007_0737

Affected Products

Openssh
Red Hat