That would be a huge problem.
I don’t care about DoS or crashes!
That would be a huge problem.
I don’t care about DoS or crashes!
Where locked accounts were treated as password-less accounts, and would allow direct ssh access.
In Debian's defence, this was caught in the unstable distro and never made it out to a stable release.
Be very, very concerned with any vulnerabilities that cause crashes. Someone may discover a way to control where the process points to, and now you have a way more serious issue.
It was a relatively recent exploit, I remember being at an RSA conference when the remote ssh exploit was announced and everyone’s pager started going off and people hustled out of there. Fun times!
Though I think I heard some criticism of what counts and what does not for that tally, maybe 20 years ago.
The project was fairly innovative of including now-standard practices like having the daemon drop its privileges.
Very unfair of OpenBSD (and other security conscious OSes) to not compete on equal terms there.