OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
BID:2825
Info
OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
| Bugtraq ID: | 2825 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 04 2001 12:00AM |
| Updated: | Jun 04 2001 12:00AM |
| Credit: | This vulnerability was first announced to Bugtraq by zen-parse <[email protected]> on June 4, 2001. |
| Vulnerable: |
OpenBSD OpenSSH 2.9 p1 OpenBSD OpenSSH 2.9 OpenBSD OpenSSH 2.5.2 p2 OpenBSD OpenSSH 2.5.2 OpenBSD OpenSSH 2.3.1 OpenBSD OpenSSH 2.2 .0 OpenBSD OpenSSH 2.1.1 |
| Not Vulnerable: | |
Discussion
OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
OpenSSH is the free implementation of the SSH client and server protocol. It is maintained by the OpenBSD project, and distributed freely as open source software.
A problem with OpenSSH makes it possible to delete arbitrary files. By connecting to a system over ssh and using X11 forwarding, a file is created in the /tmp directory as a result of the X11 forwarding. By linking the directory contained in /tmp to another directory containing the file "cookie", the cookie file will be removed by sshd upon termination of the session.
This makes it possible for a local user to arbitrary delete a cookie file belonging to another user.
OpenSSH is the free implementation of the SSH client and server protocol. It is maintained by the OpenBSD project, and distributed freely as open source software.
A problem with OpenSSH makes it possible to delete arbitrary files. By connecting to a system over ssh and using X11 forwarding, a file is created in the /tmp directory as a result of the X11 forwarding. By linking the directory contained in /tmp to another directory containing the file "cookie", the cookie file will be removed by sshd upon termination of the session.
This makes it possible for a local user to arbitrary delete a cookie file belonging to another user.
Exploit / POC
OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
See discussion.
See discussion.
Solution / Fix
OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
Solution:
NetBSD Solution:
For NetBSD-current:
If you are using the in-tree sshd(8) in /usr/sbin/sshd, upgrade the binary using source code more recent than June 14, 2001. If you are using anonymous CVS, the following steps should upgrade the binaries.
# cd src
# cvs update -d -P crypto/dist/ssh usr.bin/ssh
# cd usr.bin/ssh
# make cleandir; make obj; make dependall
# make install
For NetBSD 1.5:
If you are using the in-tree sshd(8) in /usr/sbin/sshd, upgrade the binary using source code more recent than June 25, 2001. If you are using anonymous CVS, the following steps should upgrade the binaries.
# cd src
# cvs update -d -P -r netbsd-1-5 crypto/dist/ssh usr.bin/ssh
# cd usr.bin/ssh
# make cleandir; make obj; make dependall
# make install
NetBSD 1.5.1 is not vulnerable.
OpenBSD OpenSSH 2.1.1
OpenBSD OpenSSH 2.2 .0
OpenBSD OpenSSH 2.3.1
OpenBSD OpenSSH 2.5.2
OpenBSD OpenSSH 2.9
OpenBSD OpenSSH 2.9 p1
Solution:
NetBSD Solution:
For NetBSD-current:
If you are using the in-tree sshd(8) in /usr/sbin/sshd, upgrade the binary using source code more recent than June 14, 2001. If you are using anonymous CVS, the following steps should upgrade the binaries.
# cd src
# cvs update -d -P crypto/dist/ssh usr.bin/ssh
# cd usr.bin/ssh
# make cleandir; make obj; make dependall
# make install
For NetBSD 1.5:
If you are using the in-tree sshd(8) in /usr/sbin/sshd, upgrade the binary using source code more recent than June 25, 2001. If you are using anonymous CVS, the following steps should upgrade the binaries.
# cd src
# cvs update -d -P -r netbsd-1-5 crypto/dist/ssh usr.bin/ssh
# cd usr.bin/ssh
# make cleandir; make obj; make dependall
# make install
NetBSD 1.5.1 is not vulnerable.
OpenBSD OpenSSH 2.1.1
-
OpenBSD sshcookie patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/006_sshcookie.pat ch
OpenBSD OpenSSH 2.2 .0
-
OpenBSD sshcookie patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/006_sshcookie.pat ch
OpenBSD OpenSSH 2.3.1
-
OpenBSD sshcookie patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/006_sshcookie.pat ch
OpenBSD OpenSSH 2.5.2
-
OpenBSD sshcookie patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/006_sshcookie.pat ch
OpenBSD OpenSSH 2.9
-
OpenBSD sshcookie patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/006_sshcookie.pat ch
OpenBSD OpenSSH 2.9 p1
-
Caldera eServer 2.3.1 openssh-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS/openssh-2.9 p2-3.i386.rpm -
Caldera eServer 2.3.1 openssh-askpass-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS/openssh-ask pass-2.9p2-3.i386.rpm -
Caldera eServer 2.3.1 openssh-server-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS/openssh-ser ver-2.9p2-3.i386.rpm -
Caldera OpenLinux 3.1 Server openssh-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/op enssh-2.9p2-3.i386.rpm -
Caldera OpenLinux 3.1 Server openssh-askpass-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/op enssh-askpass-2.9p2-3.i386.rpm -
Caldera OpenLinux 3.1 Server openssh-server-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/op enssh-server-2.9p2-3.i386.rpm -
Caldera OpenLinux 3.1 Workstation openssh-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RP MS/openssh-2.9p2-3.i386.rpm -
Caldera OpenLinux 3.1 Workstation openssh-askpass-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RP MS/openssh-askpass-2.9p2-3.i386.rpm -
Caldera OpenLinux 3.1 Workstation openssh-server-2.9p2-3.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RP MS/openssh-server-2.9p2-3.i386.rpm
References
OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
References:
References: