Bugtraq mailing list archives

Re: URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0


From: Jaime BENJUMEA <benjumea () dte us es>
Date: Sat, 21 Jul 2001 18:26:48 +0200 (CEST)


Stephanie Thomas wrote:


A potential remote root exploit has been discovered 
in SSH Secure Shell 3.0.0, for Unix only, concerning 
accounts with password fields consisting of two or 
fewer characters. Unauthorized users could potentially 
log in to these accounts using any password, including 
an empty password.  This affects SSH Secure Shell 3.0.0
for Unix only.  This is a problem with password 

Does anybody know if previous versions (2.4) are also affected?




Current thread: