Multiple Vendor SSH2 Implementation Buffer Overflow Vulnerabilities
BID:6407
Info
Multiple Vendor SSH2 Implementation Buffer Overflow Vulnerabilities
| Bugtraq ID: | 6407 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1359 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | Discovery of this vulnerability is credited to Rapid 7, Inc. |
| Vulnerable: |
WinSCP WinSCP 2.0 .0 Simon Tatham PuTTY 0.53 Simon Tatham PuTTY 0.49 Simon Tatham PuTTY 0.48 Pragma Systems SecureShell 2.0 NetComposite Shellguard SSH 3.4.6 InterSoft SecureNetTerm 5.4.1 FiSSH SSH Client For Windows 1.0 A Cisco WebNS 7.10 Cisco WebNS 7.1 0.2.06 Cisco WebNS 7.1 0.1.02 Cisco WebNS 5.20 Cisco WebNS 5.10 Cisco WebNS 5.1 0.0.10 Cisco PIX Firewall 6.2.2 .111 Cisco PIX Firewall 6.2.2 Cisco PIX Firewall 6.2.1 Cisco PIX Firewall 6.2 (2) Cisco PIX Firewall 6.2 (1) Cisco PIX Firewall 6.2 Cisco PIX Firewall 6.1.4 Cisco PIX Firewall 6.1.3 Cisco PIX Firewall 6.1 (4) Cisco PIX Firewall 6.1 (3) Cisco PIX Firewall 6.1 (2) Cisco PIX Firewall 6.1 (1) Cisco PIX Firewall 6.1 Cisco PIX Firewall 6.0.4 Cisco PIX Firewall 6.0.3 Cisco PIX Firewall 6.0 (4) Cisco PIX Firewall 6.0 (2) Cisco PIX Firewall 6.0 (1) Cisco PIX Firewall 6.0 Cisco ONS 15600 1.3 (0) Cisco ONS 15600 1.1 (1) Cisco ONS 15600 1.1 (0) Cisco ONS 15600 1.1 Cisco ONS 15600 1.0 Cisco ONS 15454SDH 4.6 (1) Cisco ONS 15454SDH 4.6 (0) Cisco ONS 15454SDH 4.5 Cisco ONS 15454SDH 4.1 (3) Cisco ONS 15454SDH 4.1 (2) Cisco ONS 15454SDH 4.1 (1) Cisco ONS 15454SDH 4.1 (0) Cisco ONS 15454SDH 4.0 (2) Cisco ONS 15454SDH 4.0 (1) Cisco ONS 15454SDH 4.0 (0) Cisco ONS 15454SDH 4.0 Cisco ONS 15454SDH 3.4 Cisco ONS 15454SDH 3.3 Cisco ONS 15454SDH 3.2 Cisco ONS 15454SDH 3.1 Cisco ONS 15454SDH 2.3 (5) Cisco ONS 15454E Optical Transport Platform 0 Cisco ONS 15454 Optical Transport Platform 4.14 Cisco ONS 15454 Optical Transport Platform 4.6 (1) Cisco ONS 15454 Optical Transport Platform 4.6 (0) Cisco ONS 15454 Optical Transport Platform 4.5 Cisco ONS 15454 Optical Transport Platform 4.1 (3) Cisco ONS 15454 Optical Transport Platform 4.1 (2) Cisco ONS 15454 Optical Transport Platform 4.1 (1) Cisco ONS 15454 Optical Transport Platform 4.1 (0) Cisco ONS 15454 Optical Transport Platform 4.1 Cisco ONS 15454 Optical Transport Platform 4.0 (2) Cisco ONS 15454 Optical Transport Platform 4.0 (1) Cisco ONS 15454 Optical Transport Platform 4.0 Cisco ONS 15454 Optical Transport Platform 3.4 Cisco ONS 15454 Optical Transport Platform 3.3 Cisco ONS 15454 Optical Transport Platform 3.2 .0 Cisco ONS 15454 Optical Transport Platform 3.1 .0 Cisco ONS 15454 Optical Transport Platform 3.0 Cisco ONS 15454 Optical Transport Platform 2.3 (5) Cisco ONS 15454 IOS-Based Blades Cisco ONS 15327 Metro Edge Optical Transport Platform Cisco ONS 15327 4.14 Cisco ONS 15327 4.6 (1) Cisco ONS 15327 4.6 (0) Cisco ONS 15327 4.1 (3) Cisco ONS 15327 4.1 (2) Cisco ONS 15327 4.1 (1) Cisco ONS 15327 4.1 (0) Cisco ONS 15327 4.0 (2) Cisco ONS 15327 4.0 (1) Cisco ONS 15327 4.0 Cisco ONS 15327 3.4 Cisco ONS 15327 3.3 Cisco ONS 15327 3.2 Cisco ONS 15327 3.1 Cisco ONS 15327 3.0 Cisco IOS 12.2T Cisco IOS 12.2S Cisco IOS 12.2(1)T Cisco IOS 12.2(1)S Cisco IOS 12.2(1) Cisco IOS 12.2 Cisco IOS 12.1T Cisco IOS 12.1EA Cisco IOS 12.1E Cisco IOS 12.1(5a)E Cisco IOS 12.1(1)T Cisco IOS 12.0ST Cisco IOS 12.0S Cisco IOS 12.0(5)S Cisco IOS 12.0(16)ST Cisco Firewall Services Module (FWSM) 2.1 (0.208) Cisco Aironet Firmware 12.0 1T Cisco Aironet Firmware 12.0 0T |
| Not Vulnerable: |
Simon Tatham PuTTY 0.53 b Pragma Systems SecureShell 3.0 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 LSH LSH 1.5 InterSoft SecureNetTerm 5.4.2 Cisco WebNS 7.10 .0.06s Cisco WebNS 5.20 .0.06s Cisco PIX Firewall 6.3 (1) Cisco PIX Firewall 6.2 (3) Cisco PIX Firewall 6.1 (5) Cisco PIX Firewall 6.0 (4.101) Cisco IOS 12.2(14)S Cisco IOS 12.2(13a) Cisco IOS 12.2(13)T1 Cisco IOS 12.2(12b) Cisco IOS 12.2(11)T3 Cisco IOS 12.1(14)E1 Cisco IOS 12.1(13)EA1c Cisco IOS 12.1(13)E3 Cisco IOS 12.0(23)S2 Cisco IOS 12.0(22)S4 Cisco IOS 12.0(21)ST6 Cisco IOS 12.0(21)S6 Cisco IOS 12.0(20)ST7 Cisco Aironet Firmware 12.0 1T1 BitVise WinSSHD 3.5 |
Discussion
Multiple Vendor SSH2 Implementation Buffer Overflow Vulnerabilities
Multiple vendor SSH2 implementations are reported to be prone to buffer overflows. These buffer overflows are alleged to be exploitable prior to authentication.
These conditions were discovered during tests of the initialization, key exchange, and negotiation phases (KEX, KEXINIT) of a SSH2 transaction between client and server. These issues are known to affect various client and server implementations of the protocol.
Successful exploitation will enable remote attackers to cause execution of code in the security context of the specific server and client implementations.
Further details about this vulnerability are currently unknown. This BID will be updated as more information becomes available. This vulnerability was originally described in BugTraq ID 6397.
Multiple vendor SSH2 implementations are reported to be prone to buffer overflows. These buffer overflows are alleged to be exploitable prior to authentication.
These conditions were discovered during tests of the initialization, key exchange, and negotiation phases (KEX, KEXINIT) of a SSH2 transaction between client and server. These issues are known to affect various client and server implementations of the protocol.
Successful exploitation will enable remote attackers to cause execution of code in the security context of the specific server and client implementations.
Further details about this vulnerability are currently unknown. This BID will be updated as more information becomes available. This vulnerability was originally described in BugTraq ID 6397.
Exploit / POC
Multiple Vendor SSH2 Implementation Buffer Overflow Vulnerabilities
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
Proof-of-concept code has been published. The following program will act as a malicious server to exploit vulnerable 'putty' clients.
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
Proof-of-concept code has been published. The following program will act as a malicious server to exploit vulnerable 'putty' clients.
Solution / Fix
Multiple Vendor SSH2 Implementation Buffer Overflow Vulnerabilities
Solution:
Cray Inc. supports an OpenSSH implementation via the Cray Open Software (COS) package. COS 3.3 will reportedly address these issues and is expected to be released at the end of December 2002. Those affected by the issues may also contact Cray Inc. to obtain a fixed version of the OpenSSH implementation that will be made available in COS 3.3.
SSH Secure Shell products do not appear to be prone to any of the vulnerabilities that have been reported.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial of service attacks via exploitation of these issues.
Some versions of Cisco IOS support SSH, though it is not enabled by default. Fixed versions have been made available. See the referenced advisory for more information.
Cisco has released an updated advisory. Cisco Aironet software rebuild version 12.01T1 is not vulnerable to this issue. This software will be available in the near future and will be available for download from the Software Center.
http://www.cisco.com/tacpage/sw-center/sw-wireless.shtml
Cisco has released Content Switching Software updates. WebNS 5.20.0.06s and 7.10.0.06s address the issues. These updates can be found at the following location:
http://www.cisco.com/tacpage/sw-center/sw-content.shtml
Cisco has updated their advisory to include Cisco PIX Firewall as being vulnerable. PIX Firewall has been fixed in software versions 6.0(4.101), 6.1(5), 6.2(3) and 6.3(1).
Cisco has released an updated advisory to outline vulnerable Cisco ONS products and fixes. Please see the referenced advisory for more information.
The following vendors have provided fixes:
Cisco IOS 12.2T
Cisco IOS 12.2S
Cisco IOS 12.0ST
Cisco IOS 12.2
Cisco IOS 12.1E
Cisco IOS 12.0S
Simon Tatham PuTTY 0.49
Simon Tatham PuTTY 0.53
Pragma Systems SecureShell 2.0
InterSoft SecureNetTerm 5.4.1
Solution:
Cray Inc. supports an OpenSSH implementation via the Cray Open Software (COS) package. COS 3.3 will reportedly address these issues and is expected to be released at the end of December 2002. Those affected by the issues may also contact Cray Inc. to obtain a fixed version of the OpenSSH implementation that will be made available in COS 3.3.
SSH Secure Shell products do not appear to be prone to any of the vulnerabilities that have been reported.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial of service attacks via exploitation of these issues.
Some versions of Cisco IOS support SSH, though it is not enabled by default. Fixed versions have been made available. See the referenced advisory for more information.
Cisco has released an updated advisory. Cisco Aironet software rebuild version 12.01T1 is not vulnerable to this issue. This software will be available in the near future and will be available for download from the Software Center.
http://www.cisco.com/tacpage/sw-center/sw-wireless.shtml
Cisco has released Content Switching Software updates. WebNS 5.20.0.06s and 7.10.0.06s address the issues. These updates can be found at the following location:
http://www.cisco.com/tacpage/sw-center/sw-content.shtml
Cisco has updated their advisory to include Cisco PIX Firewall as being vulnerable. PIX Firewall has been fixed in software versions 6.0(4.101), 6.1(5), 6.2(3) and 6.3(1).
Cisco has released an updated advisory to outline vulnerable Cisco ONS products and fixes. Please see the referenced advisory for more information.
The following vendors have provided fixes:
Cisco IOS 12.2T
-
Cisco IOS 12.2(11)T3
http://www.cisco.com -
Cisco IOS 12.2(13)T1
http://www.cisco.com
Cisco IOS 12.2S
-
Cisco IOS 12.2(14)S
http://www.cisco.com
Cisco IOS 12.0ST
-
Cisco IOS 12.0(20)ST7
http://www.cisco.com -
Cisco IOS 12.0(21)ST6
http://www.cisco.com
Cisco IOS 12.2
-
Cisco IOS 12.2(12b)
http://www.cisco.com -
Cisco IOS 12.2(13a)
http://www.cisco.com
Cisco IOS 12.1E
-
Cisco IOS 12.1(13)E3
http://www.cisco.com
Cisco IOS 12.0S
-
Cisco IOS 12.0(21)S6
http://www.cisco.com -
Cisco IOS 12.0(22)S4
http://www.cisco.com -
Cisco IOS 12.0(23)S2
http://www.cisco.com
Simon Tatham PuTTY 0.49
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Simon Tatham PuTTY 0.53
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Pragma Systems SecureShell 2.0
-
Pragma Systems PragmaSSHD.exe
http://www.pragmasys.com/SecureShell/Update/
InterSoft SecureNetTerm 5.4.1
-
InterSoft SecureNetTerm.exe
http://www.securenetterm.com/html/beasecurenetterm.html
References
Multiple Vendor SSH2 Implementation Buffer Overflow Vulnerabilities
References:
References:
- CERT Advisory CA-2002-36 Multiple Vulnerabilities in SSH Implementations (CERT/CC)
- Cisco Security Advisory: SSH Malformed Packet Vulnerabilities (Cisco Systems)
- F-Secure Homepage (F-Secure)
- SSH Communications Homepage (SSH Communications)
- [IPS] PUTTY SSH-Client Exploit (
) - Re: [IPS] PUTTY SSH-Client Exploit (Owen Dunn
)