漏洞信息详情
OpenSSH UseLogin漏洞
				
- CNNVD编号:CNNVD-200006-039
 - 危害等级: 超危
![图片[1]-OpenSSH UseLogin漏洞-一一网](https://www.proyy.com/skycj/data/images/2021-04-24/c4e67a37c54aee8c0e1983d8333a9158.png)
 - CVE编号:
CVE-2000-0525
 - 漏洞类型:
设计错误
 - 发布时间:
2000-06-08
 - 威胁类型:
远程
 - 更新时间:
2006-09-05
 - 厂        商:
openbsd - 漏洞来源:
First posted to Bu… - 
							
 
漏洞简介
OpenSSH在用UseLogin选项启动时无法降低权限。本地用户通过向ssh守护程序提供命令可以执行任意命令。
漏洞公告
				OpenSSH 2.1.1 is fixed and is not vulnerable to this attack. It can be obtained at:
http://www.openssh.com/ftp.html
The following software distributions have released their respective patched packages at the locations below:
RedHat Linux:
ftp://ftp.redhat.de/pub/rh-addons/security/current
Connectiva Linux:
DIRECT DOWNLOAD LINKS TO UPDATED PACKAGES
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-askpass-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-askpass-gnome-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-clients-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-server-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssl-0.9.5a-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssl-devel-0.9.5a-1cl.i386.rpm
DIRECT LINK TO THE SOURCE PACKAGE
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/SRPMS/openssh-2.1.1p1-1cl.src.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/SRPMS/openssl-0.9.5a-1cl.src.rpm
FreeBSD:
Versions of FreeBSD 4 and 5, released after June 11, 2000 contain a version of OpenSSH that is not vulnerable to this problem. For those users who do not want to download and install the latest version of OpenSSH, a patch has been made available.
			
参考网址
				来源: XF
名称: openssh-uselogin-remote-exec
链接:http://xforce.iss.net/static/4646.php
来源: BID
名称: 1334
链接:http://www.securityfocus.com/bid/1334
来源: OSVDB
名称: 341
链接:http://www.osvdb.org/341
来源: OPENBSD
名称: 20000606 The non-default UseLogin feature in /etc/sshd_config is broken and should not be used.
链接:http://www.openbsd.org/errata.html#uselogin
来源: BUGTRAQ
名称: 20000609 OpenSSH’s UseLogin option allows remote access with root privilege.
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.html





















![[桜井宁宁]COS和泉纱雾超可爱写真福利集-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/4d3cf227a85d7e79f5d6b4efb6bde3e8.jpg)

![[桜井宁宁] 爆乳奶牛少女cos写真-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/d40483e126fcf567894e89c65eaca655.jpg)