Discover Cryptography News
Portable OpenSSH Security Advisory: sshpam.adv
From: Damien Miller This document can be found at: http://www.openssh.com/txt/sshpam.adv The OpenBSD releases of OpenSSH do not contain this code and are not vulnerable. Due to complexity, inconsistencies in the specification and differences between vendors' PAM implementations we recommend that PAM be left disabled in sshd_config unless there is a need for its use. Sites only using public key or simple password authentication usually have little need to enable PAM support.
To: openssh-unix-announce@mindrot.org
Cc: announce@openbsd.org, bugtraq@securityfocus.com, lwn@lwn.net, misc@openbsd.org, news@linuxsecurity.com, openssh-unix-dev@mindrot.org, pab@ct.heise.de, secureshell@securityfocus.com, technik@genua.de, timothy@monkey.org, webmaster@deadly.org
Subject: Portable OpenSSH Security Advisory: sshpam.adv