OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
BID:11781
Info
OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
| Bugtraq ID: | 11781 |
| Class: | Design Error |
| CVE: |
CVE-2003-0190 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2004 12:00AM |
| Updated: | May 08 2007 11:09PM |
| Credit: | The original discovery of this vulnerability is credited to 'Marco Ivaldi <[email protected]>'. |
| Vulnerable: |
SuSE Linux Enterprise Server 9 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 OpenSSH OpenSSH 3.9 p1 OpenSSH OpenSSH 3.8.1 p1 OpenSSH OpenSSH 3.8 p1 OpenSSH OpenSSH 3.7.1 p1 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 p2 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1-1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 |
| Not Vulnerable: | |
Discussion
OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
The portable version of OpenSSH is reported prone to an information-disclosure vulnerability. The portable version is distributed for operating systems other than its native OpenBSD platform.
This issue is related to BID 7467. Reportedly, the previous fix for BID 7467 didn't completely fix the issue. This current issue may involve differing code paths in PAM, resulting in a new vulnerability, but this has not been confirmed.
Exploiting this vulnerability allows remote attackers to test for the presence of valid usernames. Knowledge of usernames may aid them in further attacks.
The portable version of OpenSSH is reported prone to an information-disclosure vulnerability. The portable version is distributed for operating systems other than its native OpenBSD platform.
This issue is related to BID 7467. Reportedly, the previous fix for BID 7467 didn't completely fix the issue. This current issue may involve differing code paths in PAM, resulting in a new vulnerability, but this has not been confirmed.
Exploiting this vulnerability allows remote attackers to test for the presence of valid usernames. Knowledge of usernames may aid them in further attacks.
Exploit / POC
OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
The following proof-of-concept exploit is available:
The following proof-of-concept exploit is available:
Solution / Fix
OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
Solution:
Please see the references for more information and fixes.
OpenSSH OpenSSH 3.4 p1
Solution:
Please see the references for more information and fixes.
OpenSSH OpenSSH 3.4 p1
-
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_amd64.udeb -
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_i386.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_i386.udeb -
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_powerpc.udeb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_i386.deb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_i386.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_i386.udeb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_i386.deb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_i386.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu ssh_3.8.1p1-11ubuntu3.1_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_3.8.1p1-11ub untu3.1_all.deb
References
OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
References:
References: