FreeBSD : FreeBSD -- pam_ssh improperly grants access when user account has unencrypted SSH private keys (eda151d8-4638-11e1-9f47-00e0815b8da8)
Medium Nessus Plugin ID 57741
SynopsisThe remote FreeBSD host is missing one or more security-related updates.
DescriptionThe OpenSSL library call used to decrypt private keys ignores the passphrase argument if the key is not encrypted. Because the pam_ssh module only checks whether the passphrase provided by the user is null, users with unencrypted SSH private keys may successfully authenticate themselves by providing a dummy passphrase.
SolutionUpdate the affected packages.