CVE-2007-0844

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.
Configurations

Configuration 1

cpe:2.3:a:pam_ssh:pam_ssh:1.91:*:*:*:*:*:*:*

Information

Published : 2007-02-08 05:28

Updated : 2011-03-08 02:50


NVD link : CVE-2007-0844

Mitre link : CVE-2007-0844

Products Affected
No products.