Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.10771
Category:Gain a shell remotely
Title:OpenSSH 2.5.x -> 2.9.x adv.option
Summary:NOSUMMARY
Description:Description:

You are running a version of OpenSSH between 2.5.x and
2.9.x

Depending on the order of the user keys in
~
/.ssh/authorized_keys2, sshd might fail to
apply the source IP based access control
restriction to the correct key.

This problem allows users to circumvent
the system policy and login from disallowed
source IP address.

Solution :
Upgrade to OpenSSH 2.9.9

Risk factor : Medium

Cross-Ref: BugTraq ID: 3369
Common Vulnerability Exposure (CVE) ID: CVE-2001-0816
Bugtraq: 20010918 OpenSSH: sftp & bypassing keypair auth restrictions (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2001-09/0153.html
Conectiva Linux advisory: CLSA-2001:431
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000431
Immunix Linux Advisory: IMNX-2001-70-034-01
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01
http://www.osvdb.org/5536
http://www.redhat.com/support/errata/RHSA-2001-154.html
XForce ISS Database: openssh-sftp-bypass-restrictions(7634)
https://exchange.xforce.ibmcloud.com/vulnerabilities/7634
CopyrightThis script is Copyright (C) 2001 Renaud Deraison

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.