Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-0844

Опубликовано: 08 фев. 2007
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pam_ssh:pam_ssh:1.91:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00226
Низкий

6.4 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 18 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

redhat
почти 19 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

debian
больше 18 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when th ...

github
больше 3 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

EPSS

Процентиль: 45%
0.00226
Низкий

6.4 Medium

CVSS2

Дефекты

NVD-CWE-Other