OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
BID:14963
Info
OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
| Bugtraq ID: | 14963 |
| Class: | Design Error |
| CVE: |
CVE-2004-2069 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2004 12:00AM |
| Updated: | Dec 15 2006 10:53PM |
| Credit: | "Kumaresh" <[email protected]> disclosed this issue to the vendor. |
| Vulnerable: |
VMWare ESX Server 2.5.4 VMWare ESX Server 2.5.3 VMWare ESX Server 2.1.3 VMWare ESX Server 2.0.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 OpenSSH OpenSSH 3.7.1 p1 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 p2 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1-1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 OpenSSH OpenSSH 2.9.9 OpenSSH OpenSSH 2.9 p2 OpenSSH OpenSSH 2.9 p1 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5.1 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 Avaya Intuity LX Avaya Integrated Management 2.1 Avaya Integrated Management Avaya CVLAN |
| Not Vulnerable: |
VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.3 Patch 4 VMWare ESX Server 2.1.3 Patch 2 VMWare ESX Server 2.0.2 Patch 2 OpenSSH OpenSSH 3.8 p1 |
Discussion
OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
OpenSSH is susceptible to a remote denial-of-service vulnerability. This issue is due to a design flaw when servicing timeouts related to the 'LoginGraceTime' server-configuration directive.
Specifically, when 'LoginGraceTime' in conjunction with 'MaxStartups' and 'UsePrivilegeSeparation' are configured and enabled in the server, a condition may arise where the server refuses further remote connection attempts.
This issue may be exploited by remote attackers to deny SSH service to legitimate users.
OpenSSH is susceptible to a remote denial-of-service vulnerability. This issue is due to a design flaw when servicing timeouts related to the 'LoginGraceTime' server-configuration directive.
Specifically, when 'LoginGraceTime' in conjunction with 'MaxStartups' and 'UsePrivilegeSeparation' are configured and enabled in the server, a condition may arise where the server refuses further remote connection attempts.
This issue may be exploited by remote attackers to deny SSH service to legitimate users.
Exploit / POC
OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
Solution:
Please see the referenced vendor advisories for more information and fixes.
OpenSSH OpenSSH 2.3
OpenSSH OpenSSH 2.5
OpenSSH OpenSSH 2.5.1
OpenSSH OpenSSH 2.5.2
OpenSSH OpenSSH 2.9 p2
OpenSSH OpenSSH 2.9
OpenSSH OpenSSH 2.9 p1
OpenSSH OpenSSH 2.9.9
OpenSSH OpenSSH 3.0
OpenSSH OpenSSH 3.0 p1
OpenSSH OpenSSH 3.0.1 p1
OpenSSH OpenSSH 3.0.1
OpenSSH OpenSSH 3.0.2
OpenSSH OpenSSH 3.0.2 p1
OpenSSH OpenSSH 3.1
OpenSSH OpenSSH 3.1 p1
OpenSSH OpenSSH 3.2
OpenSSH OpenSSH 3.2.2 p1
OpenSSH OpenSSH 3.2.3 p1
OpenSSH OpenSSH 3.3
OpenSSH OpenSSH 3.3 p1
OpenSSH OpenSSH 3.4
OpenSSH OpenSSH 3.4 p1
OpenSSH OpenSSH 3.4 p1-1
OpenSSH OpenSSH 3.5
OpenSSH OpenSSH 3.5 p1
OpenSSH OpenSSH 3.6.1 p1
OpenSSH OpenSSH 3.6.1 p2
OpenSSH OpenSSH 3.6.1
OpenSSH OpenSSH 3.7 p1
OpenSSH OpenSSH 3.7
OpenSSH OpenSSH 3.7 .1p2
OpenSSH OpenSSH 3.7.1
OpenSSH OpenSSH 3.7.1 p1
Solution:
Please see the referenced vendor advisories for more information and fixes.
OpenSSH OpenSSH 2.3
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 2.5
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 2.5.1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 2.5.2
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 2.9 p2
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 2.9
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 2.9 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 2.9.9
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.0
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.0 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.0.1 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.0.1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.0.2
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.0.2 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.1 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz -
RedHat openssh-3.1p1-14.3.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/openssh-3.1p1 -14.3.legacy.i386.rpm -
RedHat openssh-askpass-3.1p1-14.3.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/openssh-askpa ss-3.1p1-14.3.legacy.i386.rpm -
RedHat openssh-askpass-gnome-3.1p1-14.3.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/openssh-askpa ss-gnome-3.1p1-14.3.legacy.i386.rpm -
RedHat openssh-clients-3.1p1-14.3.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/openssh-clien ts-3.1p1-14.3.legacy.i386.rpm -
RedHat openssh-server-3.1p1-14.3.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/openssh-serve r-3.1p1-14.3.legacy.i386.rpm
OpenSSH OpenSSH 3.2
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.2.2 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.2.3 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.3
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.3 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.4
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.4 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.4 p1-1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.5
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.5 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz -
RedHat openssh-3.5p1-11.4.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/openssh-3.5p1-1 1.4.legacy.i386.rpm -
RedHat openssh-askpass-3.5p1-11.4.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/openssh-askpass -3.5p1-11.4.legacy.i386.rpm -
RedHat openssh-askpass-gnome-3.5p1-11.4.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/openssh-askpass -gnome-3.5p1-11.4.legacy.i386.rpm -
RedHat openssh-clients-3.5p1-11.4.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/openssh-clients -3.5p1-11.4.legacy.i386.rpm -
RedHat openssh-server-3.5p1-11.4.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/openssh-server- 3.5p1-11.4.legacy.i386.rpm
OpenSSH OpenSSH 3.6.1 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.6.1 p2
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz -
RedHat openssh-3.6.1p2-19.4.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/openssh-3.6.1p2 -19.4.legacy.i386.rpm -
RedHat openssh-3.6.1p2-34.4.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/openssh-3.6.1p2 -34.4.legacy.i386.rpm -
RedHat openssh-askpass-3.6.1p2-19.4.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/openssh-askpass -3.6.1p2-19.4.legacy.i386.rpm -
RedHat openssh-askpass-3.6.1p2-34.4.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/openssh-askpass -3.6.1p2-34.4.legacy.i386.rpm -
RedHat openssh-askpass-gnome-3.6.1p2-19.4.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/openssh-askpass -gnome-3.6.1p2-19.4.legacy.i386.rpm -
RedHat openssh-askpass-gnome-3.6.1p2-34.4.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/openssh-askpass -gnome-3.6.1p2-34.4.legacy.i386.rpm -
RedHat openssh-clients-3.6.1p2-19.4.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/openssh-clients -3.6.1p2-19.4.legacy.i386.rpm -
RedHat openssh-clients-3.6.1p2-34.4.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/openssh-clients -3.6.1p2-34.4.legacy.i386.rpm -
RedHat openssh-server-3.6.1p2-19.4.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/openssh-server- 3.6.1p2-19.4.legacy.i386.rpm -
RedHat openssh-server-3.6.1p2-34.4.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/openssh-server- 3.6.1p2-34.4.legacy.i386.rpm
OpenSSH OpenSSH 3.6.1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.7 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.7
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.7 .1p2
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.7.1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
OpenSSH OpenSSH 3.7.1 p1
-
OpenSSH openssh-3.8.tgz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.8.tgz
References
OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
References:
References:
- ASA-2005-223 - OpenSSH security update - (RHSA-2005-550) (Avaya)
- OpenSSH - Connection problem when LoginGraceTime exceeds time ("Kumaresh"
) - OpenSSH Project Homepage (OpenSSH)
- Re: OpenSSH - Connection problem when LoginGraceTime exceeds time (Darren Tucker
) - RHSA-2005:550-6 - openssh security update (RedHat)
- VMware ESX Server 2.0.2 Upgrade Patch 2 (for 2.0.2 Systems Only) (VMWare)
- VMware ESX Server 2.1.3 Upgrade Patch 2 (for 2.1.3 Systems Only) (VMWare)
- VMware ESX Server 2.5.3 Upgrade Patch 4 (for 2.5.3 Systems Only) (VMWare)
- VMware ESX Server 2.5.4 Upgrade Patch 1 (for 2.5.4 Systems Only) (VMWare)