OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
BID:7467
Info
OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
| Bugtraq ID: | 7467 |
| Class: | Design Error |
| CVE: |
CVE-2003-0190 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2003 12:00AM |
| Updated: | Feb 22 2007 02:36AM |
| Credit: | Discovery of this vulnerability has been credited to 'Marco Ivaldi <[email protected]>'. |
| Vulnerable: |
Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Workstation 6.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Server 6.5 Turbolinux Turbolinux Server 6.1 Turbolinux Turbolinux Advanced Server 6.0 SuSE Linux Enterprise Server 9 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.1 p1 |
| Not Vulnerable: |
OpenSSH OpenSSH 3.6.1 p2 |
Discussion
OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
OpenSSH-portable with PAM support enabled has been reported prone to an information-disclosure vulnerability under certain configurative circumstances.
By analyzing the response time during authentication, remote attackers may be able to determine whether or not the supplied username is valid.
This issue may be related to the issues described in BID 7342 and BID 7343. BID 11781 may also be pertinent; it describes an issue very similar to this one.
OpenSSH-portable with PAM support enabled has been reported prone to an information-disclosure vulnerability under certain configurative circumstances.
By analyzing the response time during authentication, remote attackers may be able to determine whether or not the supplied username is valid.
This issue may be related to the issues described in BID 7342 and BID 7343. BID 11781 may also be pertinent; it describes an issue very similar to this one.
Exploit / POC
OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
The following proof-of-concept programs have been supplied:
The following proof-of-concept programs have been supplied:
Solution / Fix
OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
Solution:
UPDATE: Some fixes described in this BID may not be sufficient to completely guard against exploitation. See BID 11781 and the referenced Debian bug reports for more information.
OpenSSH OpenSSH 3.4 p1
OpenSSH OpenSSH 3.6.1 p1
Turbolinux Turbolinux Advanced Server 6.0
Turbolinux Turbolinux Workstation 6.0
Turbolinux Turbolinux Server 6.1
Turbolinux Turbolinux Server 6.5
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Server 7.0
Solution:
UPDATE: Some fixes described in this BID may not be sufficient to completely guard against exploitation. See BID 11781 and the referenced Debian bug reports for more information.
OpenSSH OpenSSH 3.4 p1
-
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_amd64.udeb -
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_i386.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_i386.udeb -
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_powerpc.udeb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_i386.deb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_i386.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_i386.udeb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_i386.deb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_i386.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu ssh_3.8.1p1-11ubuntu3.1_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_3.8.1p1-11ub untu3.1_all.deb
OpenSSH OpenSSH 3.6.1 p1
-
OpenSSH openssh-3.6.1p2.tar.gz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.6.1p2.tar .gz
Turbolinux Turbolinux Advanced Server 6.0
-
Turbolinux openssh-3.6.1p1-11.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-3.6.1p1-11.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-gnome-3.6.1p1-11.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-clients-3.6.1p1-11.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-server-3.6.1p1-11.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/
Turbolinux Turbolinux Workstation 6.0
-
Turbolinux openssh-3.6.1p1-11.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-3.6.1p1-11.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-gnome-3.6.1p1-11.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-clients-3.6.1p1-11.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-server-3.6.1p1-11.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/
Turbolinux Turbolinux Server 6.1
-
Turbolinux openssh
Turbolinux Server 6.1
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-gnome-3.6.1p1-11.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-clients-3.6.1p1-11.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-server-3.6.1p1-11.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/
Turbolinux Turbolinux Server 6.5
-
Turbolinux openssh-3.6.1p1-11.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-3.6.1p1-11.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-clients-3.6.1p1-11.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-server-3.6.1p1-11.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/
Turbolinux Turbolinux Workstation 7.0
-
Turbolinux openssh-3.6.1p1-11.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-3.6.1p1-11.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-clients-3.6.1p1-11.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-server-3.6.1p1-11.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/
Turbolinux Turbolinux Server 7.0
-
Turbolinux openssh-3.6.1p1-11.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-askpass-3.6.1p1-11.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-clients-3.6.1p1-11.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux openssh-server-3.6.1p1-11.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/
References
OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
References:
References:
- Debian Bug report logs - #248747 - sshd: no delay on successful root login with (Debian)
- RHSA-2003:224-07 Updated openssh packages available (Red Hat)
- Sun Linux Support - Sun Linux Patches (Sun)
- OpenSSH/PAM timing attack allows remote users identification (Marco Ivaldi
) - Re: OpenSSH/PAM timing attack allows remote users identification (Nicolas Couture
) - Re: OpenSSH/PAM timing attack allows remote users identification (Nicolas Couture
) - Re: OpenSSH/PAM timing attack allows remote users identification (Karl-Heinz Haag
) - Re: OpenSSH/PAM timing attack allows remote users identification (Thilo Schulz
) - Re: OpenSSH/PAM timing attack allows remote users identification (Marco Ivaldi
)