Back

MEDIUM

pam_ssh permits authentication with arbitrary string if a passphrase-less key exists

Published Feb 8, 2007

Description

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 8, 2007
Updated Aug 7, 2024
Reserved Feb 8, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Nov 7, 2006