Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Fedora 10: 2009-3500 Critical: pam_ssh SSH Authentication Issue

fedora
Calendar Grey May 2, 2009
Scroller Fedora
Ubuntu 18.04 openldap patch improves user access and experience with secure connections, boosting authentication reliability and overall system protection.

Summary

This PAM module provides single sign-on behavior for UNIX using SSH keys.

Users are authenticated by decrypting their SSH private keys with the

password provided. In the first PAM login session phase, an ssh-agent

process is started and keys are added. The same agent is used for the

following PAM sessions. In any case the appropriate environment variables

are set in the session phase.

ChangeLog:

References:

[ 1 ] Bug #492153 - CVE-2009-1273 pam_ssh: Password prompt varies for existent and non-existent users https://bugzilla.redhat.com/show_bug.cgi?id=492153

This update can be installed with the "yum" update program. Use

su -c 'yum update pam_ssh' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

http://fedoraproject.org/keys

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pam_ssh
Product: Fedora 10
Version: 1.92
Release: 10.fc10
Summary: PAM module for use with SSH keys and ssh-agent

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.