pam_ssh Unencrypted Key Authentication Bypass Vulnerability
BID:51183
Info
pam_ssh Unencrypted Key Authentication Bypass Vulnerability
| Bugtraq ID: | 51183 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2011 12:00AM |
| Updated: | Dec 23 2011 12:00AM |
| Credit: | FreeBSD |
| Vulnerable: |
pam_ssh pam_ssh 1.97 pam_ssh pam_ssh 1.92 pam_ssh pam_ssh 0 FreeBSD Freebsd 9.0-STABLE FreeBSD Freebsd 9.0-RELEASE FreeBSD Freebsd 9.0-RC3 FreeBSD Freebsd 9.0-RC1 FreeBSD Freebsd 8.2-STABLE FreeBSD Freebsd 8.2-STABLE FreeBSD Freebsd 8.2-RELEASE-p2 FreeBSD Freebsd 8.2-RELEASE-p1 FreeBSD Freebsd 8.2 - RELEASE -p3 FreeBSD Freebsd 8.2 FreeBSD Freebsd 8.1-RELEASE-p5 FreeBSD Freebsd 8.1-RELEASE-p4 FreeBSD FreeBSD 8.1-RELEASE FreeBSD FreeBSD 8.1-PRERELEASE FreeBSD Freebsd 8.1 FreeBSD Freebsd 7.4-STABLE FreeBSD Freebsd 7.4-RELEASE-p2 FreeBSD Freebsd 7.4 -RELEASE-p3 FreeBSD Freebsd 7.4 FreeBSD FreeBSD 7.3-STABLE FreeBSD Freebsd 7.3-RELEASE-p6 FreeBSD FreeBSD 7.3-RELEASE-p1 FreeBSD Freebsd 7.3 - RELEASE - p7 FreeBSD Freebsd 7.3 |
| Not Vulnerable: | |
Discussion
pam_ssh Unencrypted Key Authentication Bypass Vulnerability
pam_ssh is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication process and gain unauthorized access to the affected system.
pam_ssh is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication process and gain unauthorized access to the affected system.
Exploit / POC
pam_ssh Unencrypted Key Authentication Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
pam_ssh Unencrypted Key Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
pam_ssh Unencrypted Key Authentication Bypass Vulnerability
References:
References: