Patch for Authentication By-Pass Vulnerability in OpenSSH-2.3.1

Alok Aggarwal aggarwaa at cs.pdx.edu
Fri Feb 16 10:52:46 EST 2001


Does someone have the diffs for this development snapshot?

In protocol 2, authentication could be bypassed if public key authentication 
was permitted. This problem does exist only in OpenSSH 2.3.1. OpenSSH 2.3.0 and
versions newer than 2.3.1 are not vulnerable to this problem. 







More information about the openssh-unix-dev mailing list