PAM Authentication Execution Path Timing Information Leakage Weakness
BID:7342
Info
PAM Authentication Execution Path Timing Information Leakage Weakness
| Bugtraq ID: | 7342 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2002 12:00AM |
| Updated: | Apr 15 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Sebastian Krahmer. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 7 SuSE Linux 8.1 SuSE Linux 8.0 SuSE Linux 7.3 SuSE Linux 7.2 SuSE Linux 7.1 SuSE Linux 7.0 SuSE Linux 6.4 SuSE Linux 6.3 SuSE Linux 6.2 SuSE Linux 6.1 SuSE Linux 6.0 SuSE Linux 5.3 SuSE Linux 5.2 SuSE Linux 5.1 SuSE Linux 5.0 SuSE Linux 4.4.1 SuSE Linux 4.4 SuSE Linux 4.3 SuSE Linux 4.2 Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 _ppc Sun Solaris 2.5.1 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6_sparc Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.5 Slackware Linux 8.1 Slackware Linux 8.0 Slackware Linux 7.1 Slackware Linux 7.0 Slackware Linux 4.0 Slackware Linux 3.9 Slackware Linux 3.6 Slackware Linux 3.5 Slackware Linux 3.4 Slackware Linux 3.3 Slackware Linux 3.2 Slackware Linux 3.1 Slackware Linux 2.3 Slackware Linux 2.2 Slackware Linux 2.1 Slackware Linux 2.0.35 Slackware Linux 2.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server S.u.S.E. Linux Admin-CD for Firewall Redhat Linux 9.0 i386 Redhat Linux 8.0 Redhat Linux 7.3 Redhat Linux 7.2 Redhat Linux 7.1 Redhat Linux 7.0 Redhat Linux 6.1 Redhat Linux 6.0 Redhat Linux 5.2 Redhat Linux 5.1 Redhat Linux 5.0 Redhat Linux 4.2 Redhat Linux 4.1 Redhat Linux 4.0 Redhat Linux 3.0.3 Redhat Linux 2.1 Redhat Linux 2.0 Redhat Linux 6.2 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 2.0 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 NetBSD NetBSD 1.2.1 NetBSD NetBSD 1.2 NetBSD NetBSD 1.1 NetBSD NetBSD 1.0 Mandriva Linux Mandrake 9.1 Mandriva Linux Mandrake 9.0 Mandriva Linux Mandrake 8.2 Mandriva Linux Mandrake 8.1 Mandriva Linux Mandrake 8.0 Mandriva Linux Mandrake 7.2 Mandriva Linux Mandrake 7.1 Mandriva Linux Mandrake 7.0 Mandriva Linux Mandrake 6.1 Mandriva Linux Mandrake 6.0 MandrakeSoft Single Network Firewall 7.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 2.1 MandrakeSoft Corporate Server 1.0.1 FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.8 FreeBSD FreeBSD 4.7 -STABLE FreeBSD FreeBSD 4.7 -RELEASE FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6.2 FreeBSD FreeBSD 4.6 -STABLE FreeBSD FreeBSD 4.6 -RELEASE FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 -STABLE FreeBSD FreeBSD 4.5 -RELEASE FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 -STABLE FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 -STABLE FreeBSD FreeBSD 4.3 -RELENG FreeBSD FreeBSD 4.3 -RELEASE FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 -STABLE FreeBSD FreeBSD 4.2 -RELEASE FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 -STABLE FreeBSD FreeBSD 4.1.1 -RELEASE FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 FreeBSD FreeBSD 3.5.1 -STABLE FreeBSD FreeBSD 3.5.1 -RELEASE FreeBSD FreeBSD 3.5.1 FreeBSD FreeBSD 3.5 -STABLE FreeBSD FreeBSD 3.5 FreeBSD FreeBSD 3.4 FreeBSD FreeBSD 3.3 FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.2 FreeBSD FreeBSD 2.1.7 .1 FreeBSD FreeBSD 2.1.6 .1 FreeBSD FreeBSD 2.1.6 FreeBSD FreeBSD 2.1.5 Debian Linux 3.0 Debian Linux 2.3 Debian Linux 2.2 r3 Debian Linux 2.2 r2 Debian Linux 2.2 r1 Debian Linux 2.2 Debian Linux 2.1 Debian Linux 2.0 |
| Not Vulnerable: | |
Discussion
PAM Authentication Execution Path Timing Information Leakage Weakness
A timing attack has been described in Pluggable Authentication Modules (PAM) that could allow a remote user to determine if a username is valid. PAM could also disclose details as to whether a valid username has privileged or restricted access to the system. This information can be ascertained through analysis of the response time during PAM authentication.
This issue could occur in any services that rely on PAM for authentication.
A comprehensive list of affected PAM implementations is not available at this time. It is also not known whether this issue has been addressed in some PAM implementations.
A timing attack has been described in Pluggable Authentication Modules (PAM) that could allow a remote user to determine if a username is valid. PAM could also disclose details as to whether a valid username has privileged or restricted access to the system. This information can be ascertained through analysis of the response time during PAM authentication.
This issue could occur in any services that rely on PAM for authentication.
A comprehensive list of affected PAM implementations is not available at this time. It is also not known whether this issue has been addressed in some PAM implementations.
Exploit / POC
PAM Authentication Execution Path Timing Information Leakage Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PAM Authentication Execution Path Timing Information Leakage Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PAM Authentication Execution Path Timing Information Leakage Weakness
References:
References:
- Execution path timing analysis of UNIX daemons (Sebastian Krahmer)
- bsdbsdftpd-6.0-ssl-0.6.1-1 attack allows remote users identification (NetExpress
) - Re: bsdbsdftpd-6.0-ssl-0.6.1-1 attack allows remote users identification (Damian Gerow
) - Re: bsdbsdftpd-6.0-ssl-0.6.1-1 attack allows remote users identification (NetExpress
) - Re: bsdbsdftpd-6.0-ssl-0.6.1-1 attack allows remote users identification (Mika =?iso-8859-15?Q?Bostr=F6m?=
)