OpenSSH Visible Password Vulnerability
BID:6168
Info
OpenSSH Visible Password Vulnerability
| Bugtraq ID: | 6168 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 12 2002 12:00AM |
| Updated: | Nov 12 2002 12:00AM |
| Credit: | Vulnerability referenced in a SuSE Security Advisory. |
| Vulnerable: |
SuSE Linux 7.3 SuSE Linux 7.2 SuSE Linux 7.1 SuSE Linux 7.0 |
| Not Vulnerable: |
SuSE Linux 8.1 SuSE Linux 8.0 |
Discussion
OpenSSH Visible Password Vulnerability
It has been discovered that the OpenSSH daemon fails to disable terminal echoing when a user is required to renew an expired password. As a result, the cleartext password may be disclosed to an adversary in close physical proximity to the victim (or one who can otherwise observe terminal output).
It is not yet known which versions of OpenSSH are vulnerable to this issue, although it has been confrimed that SuSE 7.0 through 7.3 are affected.
It has been discovered that the OpenSSH daemon fails to disable terminal echoing when a user is required to renew an expired password. As a result, the cleartext password may be disclosed to an adversary in close physical proximity to the victim (or one who can otherwise observe terminal output).
It is not yet known which versions of OpenSSH are vulnerable to this issue, although it has been confrimed that SuSE 7.0 through 7.3 are affected.
Exploit / POC
OpenSSH Visible Password Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
OpenSSH Visible Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.