SSH Short Password Login Vulnerability
BID:3078
Info
SSH Short Password Login Vulnerability
| Bugtraq ID: | 3078 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2001 12:00AM |
| Updated: | Jul 21 2001 12:00AM |
| Credit: | Reported in a SSH Security Advisory on July 21, 2001. |
| Vulnerable: |
SSH Communications Security SSH2 3.0 |
| Not Vulnerable: | |
Discussion
SSH Short Password Login Vulnerability
An input validation error exists in version 3.0.0 of the SSH daemon (sshd) running on Unix platforms.
It may be possible for remote users to log in to accounts for which there are two or less characters in the password field of the system password file. Due to the nature of the problem, it may be possible to log in to a vulnerable system using such an account with any password. This may lead to further system compromise.
An input validation error exists in version 3.0.0 of the SSH daemon (sshd) running on Unix platforms.
It may be possible for remote users to log in to accounts for which there are two or less characters in the password field of the system password file. Due to the nature of the problem, it may be possible to log in to a vulnerable system using such an account with any password. This may lead to further system compromise.
Exploit / POC
SSH Short Password Login Vulnerability
The following script scans for vulnerable hosts running SSH 3.0.0. It was submitted by hypoclear <[email protected]>:
The following script scans for vulnerable hosts running SSH 3.0.0. It was submitted by hypoclear <[email protected]>:
Solution / Fix
SSH Short Password Login Vulnerability
Solution:
A vendor-supplied update that rectifies this issue is available:
SSH Communications Security SSH2 3.0
Solution:
A vendor-supplied update that rectifies this issue is available:
SSH Communications Security SSH2 3.0
-
SSH Communications Security SSH 3.0.1
ftp://ftp.ssh.com/pub/ssh/ssh-3.0.1.tar.gz