CVE-2007-2243: OpenSSH S/KEY Authentication Enumeration

SUMMARY

Not vulnerable.

CVE ID

CVE-2007-2243

DESCRIPTION

OpenSSH S/KEY Authentication Enumeration

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.
 

RESOLUTION

Unitrends Risk Assessment: None.  Not vulnerable.
The OpenSSH packages as shipped with Red Hat Enterprise Linux do not contain S/KEY support.



 

LINK TO ADVISORIES

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section