OpenSSH < 2.9.9 / 2.9p2 Symbolic Link 'cookies' File Removal
Low Nessus Plugin ID 44071
Local attackers may be able to delete arbitrary files.
According to the banner, OpenSSH earlier than 2.9.9 / 2.9p2 is running on the remote host. Such versions contain an arbitrary file deletion vulnerability. Due to insecure handling of temporary files, a local attacker can cause sshd to delete any file it can access named 'cookies'.