Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Dec 5, 2012 | Oct 18, 2007 |
| Oracle_linux | — | Upgrade openssh-serverUpgrade openssh-askpassUpgrade pam-develUpgrade openssh-clientsUpgrade opensshUpgrade pam | Oct 16, 2024 | Oct 18, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub