OpenSSH PAM Conversation Memory Scrubbing Weakness
BID:9040
Info
OpenSSH PAM Conversation Memory Scrubbing Weakness
| Bugtraq ID: | 9040 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 13 2003 12:00AM |
| Updated: | Nov 13 2003 12:00AM |
| Credit: | Discovery credited to Markus Kuhn. |
| Vulnerable: |
OpenSSH OpenSSH 3.7.1 p1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.6.1 p2 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0 p1 |
| Not Vulnerable: | |
Discussion
OpenSSH PAM Conversation Memory Scrubbing Weakness
A problem in the handling of PAM modules has been reported in OpenSSH. Because of this, OpenSSH may not correctly handle aborted conversations with PAM modules with the consequence that memory may not be scrubbed of sensitive information such as credentials. This could also expose other vulnerabilities in PAM modules due to unpredictable behavior.
A problem in the handling of PAM modules has been reported in OpenSSH. Because of this, OpenSSH may not correctly handle aborted conversations with PAM modules with the consequence that memory may not be scrubbed of sensitive information such as credentials. This could also expose other vulnerabilities in PAM modules due to unpredictable behavior.
Exploit / POC
OpenSSH PAM Conversation Memory Scrubbing Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenSSH PAM Conversation Memory Scrubbing Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OpenSSH PAM Conversation Memory Scrubbing Weakness
References:
References:
- Bugzilla Bug 632 (Markus Kuhn)
- Minor OpenSSH/pam vuln (non-exploitable) (
)