Vulnerabilities
Vulnerable Software
Openbsd:  >> Openssh  >> 2.3  Security Vulnerabilities
The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage return is entered, which could allow remote attackers to determine that the countermeasure is being used.
CVSS Score
5.0
EPSS Score
0.078
Published
2001-09-27
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.
CVSS Score
7.2
EPSS Score
0.006
Published
2001-08-14
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.
CVSS Score
7.5
EPSS Score
0.022
Published
2001-06-19


Contact Us

Shodan ® - All rights reserved