Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root, which makes it easier for attackers to avoid detection and can make it more difficult to conduct forensics activities.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-12-20T23:00:00

Updated: 2024-08-07T16:11:06.060Z

Reserved: 2007-12-20T00:00:00

Link: CVE-2007-6505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-12-20T23:46:00.000

Modified: 2017-09-29T01:29:58.550

Link: CVE-2007-6505

cve-icon Redhat

No data.