CVE-2003-0786
N/A
N/A
Summary
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.openssh.com/txt/sshpam.adv
- http://www.securityfocus.com/bid/8677
- http://www.securityfocus.com/archive/1/338617
- http://www.securityfocus.com/archive/1/338616
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html
- http://www.kb.cert.org/vuls/id/602204
References
- http://www.openssh.com/txt/sshpam.adv
- http://www.securityfocus.com/bid/8677
- http://www.securityfocus.com/archive/1/338617
- http://www.securityfocus.com/archive/1/338616
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html
- http://www.kb.cert.org/vuls/id/602204
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.