|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Hewlett-Packard Company Information for VU#369347
| Date Notified: | 2002-06-24 |
| Date Updated: | |
| Status Summary: | Vulnerable |
Vendor StatementHP has issued a security bulletin (HPSBUX0206-195) for HP 9000 Servers running HP-UX release 11.00 and 11.11 only with the T1471AA SSH product installed.
It says in part:
As a short-term solution, disable PAMAuthenticationViaKbdInt in the sshd_config file; i.e.,
PAMAuthenticationViaKbdInt no
NOTE: ChallengeResponseAuthentication is not used in the HP product.
HP has also issued Security Bulletin HPSBTL0207-050 for Open SSH 3.1p1 running on HP Secure OS Software for Linux.Vendor InformationThe vendor has not provided us with any further information regarding this vulnerability.
AddendumHewlett-Packard published security bulletins HPSBUX0206-195 and HPSBTL0207-050 on this issue.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |