CVE Vulnerabilities

CVE-2007-2243

Improper Authentication

Published: Apr 25, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd 3.8 3.8
Openssh Openbsd 3.8.1p1 3.8.1p1
Openssh Openbsd 4.3p2 4.3p2
Openssh Openbsd 3.2.2 3.2.2
Openssh Openbsd 3.1 3.1
Openssh Openbsd 3.0.2p1 3.0.2p1
Openssh Openbsd 4.1 4.1
Openssh Openbsd 3.8.1 3.8.1
Openssh Openbsd 2.1.1 2.1.1
Openssh Openbsd 3.7.1p2 3.7.1p2
Openssh Openbsd 3.2.3p1 3.2.3p1
Openssh Openbsd 3.1p1 3.1p1
Openssh Openbsd 2.5.1 2.5.1
Openssh Openbsd 2.9.9p2 2.9.9p2
Openssh Openbsd 3.6.1p2 3.6.1p2
Openssh Openbsd 3.9 3.9
Openssh Openbsd 3.0 3.0
Openssh Openbsd 1.2.1 1.2.1
Openssh Openbsd 2.2 2.2
Openssh Openbsd 3.2 3.2
Openssh Openbsd 3.6 3.6
Openssh Openbsd 1.2.3 1.2.3
Openssh Openbsd 3.7 3.7
Openssh Openbsd 4.0p1 4.0p1
Openssh Openbsd 3.5p1 3.5p1
Openssh Openbsd 3.0.1p1 3.0.1p1
Openssh Openbsd 4.4 4.4
Openssh Openbsd 3.7.1p1 3.7.1p1
Openssh Openbsd 2.1 2.1
Openssh Openbsd 1.2 1.2
Openssh Openbsd 3.3 3.3
Openssh Openbsd 3.2.2p1 3.2.2p1
Openssh Openbsd 3.9.1p1 3.9.1p1
Openssh Openbsd 3.0.2 3.0.2
Openssh Openbsd 3.4p1 3.4p1
Openssh Openbsd 3.6.1p1 3.6.1p1
Openssh Openbsd 3.0.1 3.0.1
Openssh Openbsd 2.9.9 2.9.9
Openssh Openbsd 3.6.1 3.6.1
Openssh Openbsd 4.1p1 4.1p1
Openssh Openbsd 1.2.2 1.2.2
Openssh Openbsd 4.2p1 4.2p1
Openssh Openbsd 4.5 4.5
Openssh Openbsd 2.9p1 2.9p1
Openssh Openbsd 2.9 2.9
Openssh Openbsd 3.7.1 3.7.1
Openssh Openbsd 1.2.27 1.2.27
Openssh Openbsd 4.2 4.2
Openssh Openbsd 2.5.2 2.5.2
Openssh Openbsd 2.3 2.3
Openssh Openbsd 3.4 3.4
Openssh Openbsd 4.4p1 4.4p1
Openssh Openbsd 4.3p1 4.3p1
Openssh Openbsd 3.5 3.5
Openssh Openbsd 2.5 2.5
Openssh Openbsd 3.0p1 3.0p1
Openssh Openbsd 3.3p1 3.3p1
Openssh Openbsd 4.3 4.3
Openssh Openbsd 4.0 4.0
Openssh Openbsd 3.9.1 3.9.1
Openssh Openbsd 2.9p2 2.9p2
Openssh Openbsd 4.6 4.6

Potential Mitigations

References