CVE-2007-0844
EPSS 0.29%
Description
The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.
How to fix CVE-2007-0844
To remediate CVE-2007-0844, upgrade the affected package to a fixed version below.
- Debian/libpam-ssh—upgrade to 1.91.0-9.2 or later
Is CVE-2007-0844 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.91.0-9.2