OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
BID:20418
Info
OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
| Bugtraq ID: | 20418 |
| Class: | Design Error |
| CVE: |
CVE-2006-5229 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2006 12:00AM |
| Updated: | Feb 14 2007 04:37PM |
| Credit: | The discovery of this vulnerability is credited to Marco Ivaldi. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Personal 10.0 OSS OpenSSH OpenSSH 4.1 p1 |
| Not Vulnerable: | |
Discussion
OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
OpenSSH reportedly contains an information-disclosure weakness. This issue resides in the portable version of OpenSSH, which is distributed for operating systems other than its native OpenBSD platform.
This issue has been confirmed as not deriving from either the Pluggable Authentication Module (PAM) issue disclosed in BID 11781 in 2004, nor the more recent Generic Security Services Application Programming Interface (GSSAPI)-based information leak outlined in BID 20245. Reportedly, it is possible to verify access credentials for users with an existing system password by measuring SSH authentication timing differences.
This weakness allows remote users to test for the existence of valid usernames with a password set. Knowledge of system users with established passwords may aid in further attacks.
OpenSSH reportedly contains an information-disclosure weakness. This issue resides in the portable version of OpenSSH, which is distributed for operating systems other than its native OpenBSD platform.
This issue has been confirmed as not deriving from either the Pluggable Authentication Module (PAM) issue disclosed in BID 11781 in 2004, nor the more recent Generic Security Services Application Programming Interface (GSSAPI)-based information leak outlined in BID 20245. Reportedly, it is possible to verify access credentials for users with an existing system password by measuring SSH authentication timing differences.
This weakness allows remote users to test for the existence of valid usernames with a password set. Knowledge of system users with established passwords may aid in further attacks.
Exploit / POC
OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
A proof-of-concept script is available.
Attackers can also manually verify the existence of this phenomenon by using a combination of a valid SSH client application and a packet-sniffing utility.
A proof-of-concept script is available.
Attackers can also manually verify the existence of this phenomenon by using a combination of a valid SSH client application and a packet-sniffing utility.
Solution / Fix
OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
References:
References:
- sshtime (Marco Ivaldi)
- Re: yet another OpenSSH timing leak? (Marco Ivaldi)
- yet another OpenSSH timing leak? (Marco Ivaldi)