OpenSSH Remote Root Authentication Timing Side-Channel Weakness
BID:7482
Info
OpenSSH Remote Root Authentication Timing Side-Channel Weakness
| Bugtraq ID: | 7482 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2003 12:00AM |
| Updated: | Aug 01 2008 04:37PM |
| Credit: | Discovery credited to Ethan Benson <[email protected]>. |
| Vulnerable: |
OpenSSH OpenSSH 3.9 p1 OpenSSH OpenSSH 3.8.1 p1 OpenSSH OpenSSH 3.8 p1 OpenSSH OpenSSH 3.7.1 p1 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 p2 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1-1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 |
| Not Vulnerable: | |
Discussion
OpenSSH Remote Root Authentication Timing Side-Channel Weakness
A timing attack has been described in OpenSSH-portable that could assist a remote user in guessing the administrative password. This issue has been reported to occur in OpenSSH-portable on Linux systems, but it may affect other platforms and versions.
A timing attack has been described in OpenSSH-portable that could assist a remote user in guessing the administrative password. This issue has been reported to occur in OpenSSH-portable on Linux systems, but it may affect other platforms and versions.
Exploit / POC
OpenSSH Remote Root Authentication Timing Side-Channel Weakness
No exploit is required for this weakness.
No exploit is required for this weakness.
Solution / Fix
OpenSSH Remote Root Authentication Timing Side-Channel Weakness
Solution:
Please see the references for details.
OpenSSH OpenSSH 3.4 p1
Solution:
Please see the references for details.
OpenSSH OpenSSH 3.4 p1
-
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_amd64.udeb -
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_i386.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_i386.udeb -
Ubuntu openssh-client-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_3.8.1p1-11ubuntu3.1_powerpc.udeb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_i386.deb -
Ubuntu openssh-client_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_3 .8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_amd64.udeb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_i386.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_i386.udeb -
Ubuntu openssh-server-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/openssh-serv er-udeb_3.8.1p1-11ubuntu3.1_powerpc.udeb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_i386.deb -
Ubuntu openssh-server_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_3 .8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_amd64.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_i386.deb -
Ubuntu ssh-askpass-gnome_3.8.1p1-11ubuntu3.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_3.8.1p1-11ubuntu3.1_powerpc.deb -
Ubuntu ssh_3.8.1p1-11ubuntu3.1_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_3.8.1p1-11ub untu3.1_all.deb
References
OpenSSH Remote Root Authentication Timing Side-Channel Weakness
References:
References:
- Debian Bug report logs - #248747 - sshd: no delay on successful root login with (Debian)
- Re: Fwd: [BID 7482, bug in OpenSSH (Still in FreeBSD-STABLE)] (des des no (Dag-Erling Smørgrav))
- Re: OpenSSH/PAM timing attack allows remote users identificatio (Ethan Benson
) - Re: OpenSSH/PAM timing attack allows remote users identification (Nicolas Couture
) - Re: OpenSSH/PAM timing attack allows remote users identification (Marco Ivaldi
)