what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

pine-cert-20020301.txt

pine-cert-20020301.txt
Posted Mar 7, 2002
Authored by Joost Pol | Site pine.nl

An off by one overflow has been discovered in the channel code of OpenSSH versions 2.0 - 3.0.2. Users with an existing user account can abuse this bug to gain root privileges. Exploitability without an existing user account has not been proven but is not considered impossible. A malicious ssh server could also use this bug to exploit a connecting vulnerable client. Fix available here.

tags | overflow, root
SHA-256 | f862fbf462b1a8965de529058ff2c189f2e7ad5ad9d1c0dde44d02b7424b0163

pine-cert-20020301.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -----------------------------------------------------------------------------
Pine Internet Security Advisory
- -----------------------------------------------------------------------------
Advisory ID : PINE-CERT-20020301
Authors : Joost Pol <joost@pine.nl>
Issue date : 2002-03-07
Application : OpenSSH
Version(s) : All versions between 2.0 and 3.0.2
Platforms : multiple
Vendor informed : 20020304
Availability : http://www.pine.nl/advisories/pine-cert-20020301.txt
- -----------------------------------------------------------------------------

Synopsis

A bug exists in the channel code of OpenSSH versions 2.0 - 3.0.2

Users with an existing user account can abuse this bug to
gain root privileges. Exploitability without an existing
user account has not been proven but is not considered
impossible. A malicious ssh server could also use this bug
to exploit a connecting vulnerable client.

Impact

HIGH: Existing users will gain root privileges.

Description

Simple off by one error. Patch included.

Solution

The OpenSSH project will shortly release version 3.1.

Upgrading to this version is highly recommended.

This version will be made available at http://www.openssh.com

The FreeBSD port of OpenSSH has been updated to reflect the
patches as supplied in this document.

OpenSSH CVS has been updated, see

http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/ \
channels.c.diff?r1=1.170&r2=1.171

Or apply the attached patch as provided by PINE Internet:

http://www.pine.nl/advisories/pine-cert-20020301.patch


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iEYEARECAAYFAjyHaKkACgkQDNrSylhGGb3p2ACfXZu3WShzGT4Mp/LgwA6AZStu
rtkAn3O83WzyNijdJ9+9OwLJxUcVj4Ld
=j+Hz
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close