SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/2193 | vdb entry |
http://marc.info/?l=bugtraq&m=92663402004280&w=2 | mailing list |
http://www.securityfocus.com/bid/277 | vdb entry patch vendor advisory |