Updated: December 11, 2001
Not Affected
The F-Secure SSH versions 2.x - 3.x calls pam_open_session regardless whether pty is requested or not. The F-Secure SSH versions 1.x don't implement PAM authentication.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
Updated: December 07, 2001
Affected
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
Notified: December 07, 2001 Updated: December 12, 2001
Not Affected
I can confirm that we are not vulnerable this due to different PAM implementation style.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.