OpenSSH Kerberos Arbitrary Privilege Elevation Vulnerability
BID:3560
Info
OpenSSH Kerberos Arbitrary Privilege Elevation Vulnerability
| Bugtraq ID: | 3560 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2001 12:00AM |
| Updated: | Nov 19 2001 12:00AM |
| Credit: | This vulnerability was originally announced to the OpenSSH Announcement List <[email protected]> by the OpenSSH Development Team, and was posted to Bugtraq by Jonas Eriksson <[email protected]> on November 19, 2001. |
| Vulnerable: |
OpenBSD OpenSSH 3.0 p1 OpenBSD OpenSSH 3.0 |
| Not Vulnerable: |
OpenBSD OpenSSH 3.0.1 p1 OpenBSD OpenSSH 3.0.1 |
Discussion
OpenSSH Kerberos Arbitrary Privilege Elevation Vulnerability
OpenSSH is a freely available implementation of the SSH client-server protocol. It is distributed and maintained by the OpenSSH team.
A problem with the software has been discovered that could allow remote users to gain unauthorized access. The level of privilege that can be obtained through this vulnerability is currently unknown. The problem is related to the Kerberos V authentication handling by the implementation.
Under some circumstances, it may be possible for an arbitrary user to gain access to a system. The only affected OpenSSH implementations are those that have compiled into the program the Kerberos V compatibility code. This is not usually built with a default compilation of OpenSSH.
OpenSSH is a freely available implementation of the SSH client-server protocol. It is distributed and maintained by the OpenSSH team.
A problem with the software has been discovered that could allow remote users to gain unauthorized access. The level of privilege that can be obtained through this vulnerability is currently unknown. The problem is related to the Kerberos V authentication handling by the implementation.
Under some circumstances, it may be possible for an arbitrary user to gain access to a system. The only affected OpenSSH implementations are those that have compiled into the program the Kerberos V compatibility code. This is not usually built with a default compilation of OpenSSH.
Solution / Fix
OpenSSH Kerberos Arbitrary Privilege Elevation Vulnerability
Solution:
The vendor has made upgrades available.
OpenSSH packages for Trustix Secure Linux do not have Kerberos support enabled. However, fixes have been provided for those users who wish to enable Kerberos support.
OpenBSD OpenSSH 3.0
OpenBSD OpenSSH 3.0 p1
Solution:
The vendor has made upgrades available.
OpenSSH packages for Trustix Secure Linux do not have Kerberos support enabled. However, fixes have been provided for those users who wish to enable Kerberos support.
OpenBSD OpenSSH 3.0
-
OpenBSD OpenSSH 3.0.1
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.0.1.tgz -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-3.1.0p1-3tr .i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-3.1.0p1-3tr .i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-3.1.0p1-3tr .i586.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpm
Source RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/SRPMS/openssh-3.1.0p1-3t r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpm
Source RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/SRPMS/openssh-3.1.0p1-3t r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpm
Source RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/SRPMS/openssh-3.1.0p1-3t r.src.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-clients-3.1 .0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-clients-3.1 .0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-clients-3.1 .0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-server-3.1. 0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-server-3.1. 0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-server-3.1. 0p1-3tr.i586.rpm
OpenBSD OpenSSH 3.0 p1
-
OpenBSD OpenSSH 3.0.1p1
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.0.1p1.tar .gz -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-3.1.0p1-3tr .i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-3.1.0p1-3tr .i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-3.1.0p1-3tr .i586.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpm
Source RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/SRPMS/openssh-3.1.0p1-3t r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpm
Source RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/SRPMS/openssh-3.1.0p1-3t r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpm
Source RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/SRPMS/openssh-3.1.0p1-3t r.src.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-clients-3.1 .0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-clients-3.1 .0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-clients-3.1 .0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-server-3.1. 0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-server-3.1. 0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-server-3.1. 0p1-3tr.i586.rpm