OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
BID:48507
Info
OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 48507 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2011 12:00AM |
| Updated: | Jul 04 2011 10:30AM |
| Credit: | Kingcope |
| Vulnerable: |
OpenSSH OpenSSH 3.5 p1 |
| Not Vulnerable: | |
Discussion
OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
OpenSSH is prone to a buffer-overflow vulnerability because the library fails to properly bounds check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application.
OpenSSH 3.5p1 running on FreeBSD 4.9 and 4.11 is vulnerable; other versions may also be affected.
OpenSSH is prone to a buffer-overflow vulnerability because the library fails to properly bounds check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application.
OpenSSH 3.5p1 running on FreeBSD 4.9 and 4.11 is vulnerable; other versions may also be affected.
Exploit / POC
OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
The following exploit codes are available:
The following exploit codes are available:
Solution / Fix
OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
References:
References:
- OpenSSH 3.5p1 Remote Root Exploit for FreeBSD (Kingcope)
- OpenSSH Homepage (OpenSSH)