1

This question relates to CVE-2015-8325.

https://access.redhat.com/security/cve/CVE-2015-8325

William Entriken
  • 543
  • 5
  • 12

1 Answers1

1

UseLogin option is disabled by default in OpenSSH for many years and I don't know about any distribution that would like to use this fail-prone and limited method of authentication, when there are much better implemented in OpenSSH (PAM, ...).

Therefore the resolution in RHEL -- the packages are affected, but not vulnerable with default (and sane) configuraiton.

Jakuje
  • 9,145
  • 2
  • 40
  • 44