OpenSSH Channel Code Off-By-One Vulnerability
BID:4241
Info
OpenSSH Channel Code Off-By-One Vulnerability
| Bugtraq ID: | 4241 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0083 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2002 12:00AM |
| Updated: | Nov 05 2007 03:25PM |
| Credit: | Credited to Joost Pol <[email protected]>. |
| Vulnerable: |
OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 2.9.9 OpenSSH OpenSSH 2.9 p2 OpenSSH OpenSSH 2.9 p1 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5.1 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 OpenSSH OpenSSH 2.2 OpenSSH OpenSSH 2.1.1 OpenSSH OpenSSH 2.1 OpenBSD OpenBSD 2.8 |
| Not Vulnerable: |
OpenSSH OpenSSH 3.1 |
Discussion
OpenSSH Channel Code Off-By-One Vulnerability
OpenSSH is a suite implementing the SSH protocol. It includes client and server software, and supports ssh and sftp. It was initially developed for BSD, but is also widely used for Linux, Solaris, and other UNIX-like operating systems.
A vulnerability has been announced in some versions of OpenSSH. An off-by-one error occurs in the channel code. A malicious client may exploit this vulnerability by connecting to a vulnerable server. Valid credentials are believed to be required, since the exploitable condition reportedly occurs after successful authentication. An examination of the code suggests this, but it has not been confirmed by the maintainer.
Administrators should assume that this can be exploited without authentication and should patch vulnerable versions immediately.
OpenSSH is a suite implementing the SSH protocol. It includes client and server software, and supports ssh and sftp. It was initially developed for BSD, but is also widely used for Linux, Solaris, and other UNIX-like operating systems.
A vulnerability has been announced in some versions of OpenSSH. An off-by-one error occurs in the channel code. A malicious client may exploit this vulnerability by connecting to a vulnerable server. Valid credentials are believed to be required, since the exploitable condition reportedly occurs after successful authentication. An examination of the code suggests this, but it has not been confirmed by the maintainer.
Administrators should assume that this can be exploited without authentication and should patch vulnerable versions immediately.