OpenSSH 'sftp-server.c' Remote Security Bypass Vulnerability
BID:101552
Info
OpenSSH 'sftp-server.c' Remote Security Bypass Vulnerability
| Bugtraq ID: | 101552 |
| Class: | Design Error |
| CVE: |
CVE-2017-15906 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2017 12:00AM |
| Updated: | May 02 2018 12:00PM |
| Credit: | Michal Zalewski. |
| Vulnerable: |
Oracle Linux 7.0 OpenSSH OpenSSH 4.2 OpenSSH OpenSSH 4.1 OpenSSH OpenSSH 4.0 p1 OpenSSH OpenSSH 4.0 OpenSSH OpenSSH 3.9 p1 OpenSSH OpenSSH 3.8.1 p1 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1-5 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 OpenSSH OpenSSH 2.2 .0p1 OpenSSH OpenSSH 2.2 OpenSSH OpenSSH 2.1.1 OpenSSH OpenSSH 2.1 OpenSSH OpenSSH 1.2.3 OpenSSH OpenSSH 1.2.2 OpenSSH OpenSSH 7.4 OpenSSH OpenSSH 7.3 OpenSSH OpenSSH 7.2 OpenSSH OpenSSH 7.1p1 OpenSSH OpenSSH 7.1 OpenSSH OpenSSH 7.0 OpenSSH OpenSSH 6.9p1 OpenSSH OpenSSH 6.9 OpenSSH OpenSSH 6.8 OpenSSH OpenSSH 6.7 OpenSSH OpenSSH 6.6 OpenSSH OpenSSH 6.5 OpenSSH OpenSSH 6.4 OpenSSH OpenSSH 6.3 OpenSSH OpenSSH 6.2 OpenSSH OpenSSH 6.1 OpenSSH OpenSSH 6.0 OpenSSH OpenSSH 5.8 p2 OpenSSH OpenSSH 5.8 OpenSSH OpenSSH 5.7 OpenSSH OpenSSH 5.6 OpenSSH OpenSSH 5.5 OpenSSH OpenSSH 5.4 OpenSSH OpenSSH 5.3 OpenSSH OpenSSH 5.1 OpenSSH OpenSSH 5.0 OpenSSH OpenSSH 4.9 OpenSSH OpenSSH 4.8 OpenSSH OpenSSH 4.7 OpenSSH OpenSSH 4.6 OpenSSH OpenSSH 4.5 OpenSSH OpenSSH 4.4.p1 OpenSSH OpenSSH 4.4 OpenSSH OpenSSH 4.3.0 OpenSSH OpenSSH 4.2p1 OpenSSH OpenSSH 1.127 OpenSSH OpenSSH 1.126 IBM Vios 2.2.3 IBM Vios 2.2.1 4 IBM Vios 2.2 IBM Vios 2.2.4.0 IBM Vios 2.2.3.50 IBM Vios 2.2.3.4 IBM Vios 2.2.3.3 IBM Vios 2.2.3.2 IBM Vios 2.2.3.0 IBM Vios 2.2.2.6 IBM Vios 2.2.2.5 IBM Vios 2.2.2.4 IBM Vios 2.2.2.0 IBM Vios 2.2.1.9 IBM Vios 2.2.1.8 IBM Vios 2.2.1.3 IBM Vios 2.2.1.1 IBM Vios 2.2.1.0 IBM Vios 2.2.0.13 IBM Vios 2.2.0.12 IBM Vios 2.2.0.11 IBM Vios 2.2.0.10 IBM Aix 7.2 IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3 Bluecoat Security Analytics 7.3 Bluecoat Security Analytics 7.2 Bluecoat Malware Analysis Appliance 4.2 Bluecoat Director 6.1 |
| Not Vulnerable: |
OpenSSH OpenSSH 7.6 |
Discussion
OpenSSH 'sftp-server.c' Remote Security Bypass Vulnerability
OpenSSH is prone to a remote security-bypass vulnerability.
Attackers can exploit this issue to perform unauthorized actions. This may aid in further attacks.
Versions prior to OpenSSH 7.6 are vulnerable.
Note: This issue was previously titled 'OpenSSH 'sftp-server' Remote Security Vulnerability'. The title has been changed to better reflect the vulnerability information.
OpenSSH is prone to a remote security-bypass vulnerability.
Attackers can exploit this issue to perform unauthorized actions. This may aid in further attacks.
Versions prior to OpenSSH 7.6 are vulnerable.
Note: This issue was previously titled 'OpenSSH 'sftp-server' Remote Security Vulnerability'. The title has been changed to better reflect the vulnerability information.
Exploit / POC
OpenSSH 'sftp-server.c' Remote Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSSH 'sftp-server.c' Remote Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenSSH 'sftp-server.c' Remote Security Bypass Vulnerability
References:
References:
- OpenSSH Homepage (OpenSSH)
- release notes ( OpenSSH )
- OpenSSH Security (OpenSSH)
- Oracle Linux Bulletin - April 2018 (Oracle)
- SA163: OpenSSH Vulnerability October 2017 (Symantec)
- Vulnerability in OpenSSH affects AIX. (IBM)