CVE-2007-0844
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/02/2007
Last modified:
09/04/2025
Description
The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.
Impact
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pam_ssh:pam_ssh:1.91:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/33119
- http://secunia.com/advisories/24061
- http://sourceforge.net/project/shownotes.php?release_id=484376
- http://www.securityfocus.com/bid/22461
- http://www.vupen.com/english/advisories/2007/0524
- http://osvdb.org/33119
- http://secunia.com/advisories/24061
- http://sourceforge.net/project/shownotes.php?release_id=484376
- http://www.securityfocus.com/bid/22461
- http://www.vupen.com/english/advisories/2007/0524



