Dear Secure Shell Community,

A potential remote root exploit has been discovered in SSH Secure Shell 3.0.0, for Unix only, concerning accounts with password fields consisting of two or fewer characters. Unauthorized users could potentially log in to these accounts using any password, including an empty password. This affects SSH Secure Shell 3.0.0 for Unix only. This is a problem with password authentication to the sshd2 daemon. The SSH Secure Shell client binaries (located by default in /usr/local/bin) are not affected.

SSH Secure Shell 3.0.1 fixes this problem.

Url : Article complet

Site : Help Bet Security

Partagez cet article sur les réseaux sociaux