The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T02:05:12.644Z
Reserved: 2003-09-17T00:00:00
Link: CVE-2003-0786

No data.

Status : Deferred
Published: 2003-11-17T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2003-0786

No data.