Operating System - HP-UX
1834798 Members
2814 Online
110070 Solutions
New Discussion

[Security Alert] OpenSSH versions < 3.1 vulnerable

 
Steven Sim Kok Leong
Honored Contributor

[Security Alert] OpenSSH versions < 3.1 vulnerable

Hi all,

For your notice.

Hope this helps. Regards.

Extract from securityspace daily news:
====================================================================
Title: OpenSSH Channel Code Off by 1
ID: 10883
Category: Gain root remotely
URL: http://www.securityspace.com/smysecure/catid.html?id=10883

Versions prior than 3.1 are vulnerable to an off by one error that allows local users to gain root access, and it may be possible for remote users to similarly compromise the daemon for remote access.

In addition, a vulnerable SSH client may be compromised by connecting to a malicious SSH daemon that exploits this vulnerability in the client code, thus compromising the client system.

Solution : Upgrade to OpenSSH 3.1 or apply the patch for prior versions. (See: http://www.openssh.org)

Risk factor : High
====================================================================
1 REPLY 1
Craig Rants
Honored Contributor

Re: [Security Alert] OpenSSH versions < 3.1 vulnerable

Steven,
Any CERT notification on this, I get their emails and haven't seen one?

Thanks,
Craig
"In theory, there is no difference between theory and practice. But, in practice, there is. " Jan L.A. van de Snepscheut