CVE-2014-9278

The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
1:9.2p1-2+deb12u3
fixed
bookworm (security)
1:9.2p1-2+deb12u3
fixed
bullseye
1:8.4p1-5+deb11u3
fixed
bullseye (security)
1:8.4p1-5+deb11u3
fixed
sid
1:9.9p1-3
fixed
trixie
1:9.9p1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
lucid
not-affected
precise
not-affected
trusty
not-affected
utopic
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 7
0:6.6.1p1-11.el7
fixed
openssh-askpass
RHEL 7
0:6.6.1p1-11.el7
fixed
openssh-clients
RHEL 7
0:6.6.1p1-11.el7
fixed
openssh-keycat
RHEL 7
0:6.6.1p1-11.el7
fixed
openssh-ldap
RHEL 7
0:6.6.1p1-11.el7
fixed
openssh-server
RHEL 7
0:6.6.1p1-11.el7
fixed
openssh-server-sysvinit
RHEL 7
0:6.6.1p1-11.el7
fixed
pam
RHEL 7
0:0.9.3-9.11.el7
fixed