|
|
Subscribe / Log in / New account

pam_ssh: information (user account existence) leak

Package(s):pam_ssh CVE #(s):CVE-2009-1273
Created:May 4, 2009 Updated:May 6, 2009
Description:

From the Red Hat bugzilla:

A security flaw was found in PAM module, providing user authentication based on SSH keys. A remote attacker could use this flaw to recognize, if some username/login belongs to set of user accounts, existing on the system, and subsequently perform dictionary based password guess attack.

Alerts:
Fedora FEDORA-2009-3500 pam_ssh 2009-04-13
Fedora FEDORA-2009-3627 pam_ssh 2009-04-13

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds