Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2007-0844

Опубликовано: 07 нояб. 2006
Источник: redhat
EPSS Низкий

Описание

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=430487pam_ssh permits authentication with arbitrary string if a passphrase-less key exists

EPSS

Процентиль: 51%
0.00275
Низкий

Связанные уязвимости

ubuntu
почти 19 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

nvd
почти 19 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

debian
почти 19 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when th ...

github
больше 3 лет назад

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

EPSS

Процентиль: 51%
0.00275
Низкий