what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

OpenPKG Security Advisory 2006.3

OpenPKG Security Advisory 2006.3
Posted Feb 20, 2006
Authored by OpenPKG Foundation | Site openpkg.org

OpenPKG Security Advisory - Ulrich Drepper discovered [0] a weakness in OpenSSH [1] version 4.2p1 and earlier, caused due to the insecure use of the system(3) function in scp(1) when performing copy operations using filenames that are supplied by the user from the command line. This can be exploited to execute shell commands with privileges of the user running scp(1).

tags | advisory, shell
SHA-256 | ee13382478b98d5e9881b80b1408c8c48aeeed9bf2b32c680e97029ede7b0f16

OpenPKG Security Advisory 2006.3

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

________________________________________________________________________

OpenPKG Security Advisory The OpenPKG Project
http://www.openpkg.org/security.html http://www.openpkg.org
openpkg-security@openpkg.org openpkg@openpkg.org
OpenPKG-SA-2006.003 18-Feb-2006
________________________________________________________________________

Package: openssh
Vulnerability: arbitrary shell command excecution
OpenPKG Specific: no

Affected Releases: Affected Packages: Corrected Packages:
OpenPKG CURRENT <= openssh-4.2p1-20060101 >= openssh-4.3p1-20060201
OpenPKG 2.5 <= openssh-4.2p1-2.5.1 >= openssh-4.2p1-2.5.2
OpenPKG 2.4 <= openssh-4.1p1-2.4.1 >= openssh-4.1p1-2.4.2
OpenPKG 2.3 <= openssh-3.9p1-2.3.0 >= openssh-3.9p1-2.3.1

Description:
Ulrich Drepper discovered [0] a weakness in OpenSSH [1] version 4.2p1
and earlier, caused due to the insecure use of the system(3) function
in scp(1) when performing copy operations using filenames that are
supplied by the user from the command line. This can be exploited to
execute shell commands with privileges of the user running scp(1). The
Common Vulnerabilities and Exposures (CVE) project assigned the id
CVE-2006-0225 [2] to the problem.
________________________________________________________________________

References:
[0] https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168167
[1] http://www.openssh.com/
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0225
________________________________________________________________________

For security reasons, this advisory was digitally signed with the
OpenPGP public key "OpenPKG <openpkg@openpkg.org>" (ID 63C4CB9F) of the
OpenPKG project which you can retrieve from http://pgp.openpkg.org and
hkp://pgp.openpkg.org. Follow the instructions on http://pgp.openpkg.org/
for details on how to verify the integrity of this advisory.
________________________________________________________________________

-----BEGIN PGP SIGNATURE-----
Comment: OpenPKG <openpkg@openpkg.org>

iD8DBQFD9xQTgHWT4GPEy58RAmGhAJwPqGodxa5SWCErCK85VrzAhYMPUACfXeXy
h8vuY68O3h7SD1LpSCP/oHE=
=POPO
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close