|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
Any SSH server may contain a flaw that may allow a malicious user to log in without authorization. The issue is triggered when an .rhosts file is used for authentication. It is possible that the flaw may allow unauthorized login resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
OSVDB:
Best Practice
|
|
Solution |
It is possible to correct the flaw by implementing the following workaround(s): Disable .rhosts authentication.
|
|
Products |
|
SSH Server
 |
All Versions |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|