OpenSSH UseLogin漏洞

漏洞信息详情

OpenSSH UseLogin漏洞

漏洞简介

OpenSSH在用UseLogin选项启动时无法降低权限。本地用户通过向ssh守护程序提供命令可以执行任意命令。

漏洞公告

OpenSSH 2.1.1 is fixed and is not vulnerable to this attack. It can be obtained at:
http://www.openssh.com/ftp.html
The following software distributions have released their respective patched packages at the locations below:
RedHat Linux:
ftp://ftp.redhat.de/pub/rh-addons/security/current
Connectiva Linux:
DIRECT DOWNLOAD LINKS TO UPDATED PACKAGES
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-askpass-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-askpass-gnome-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-clients-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssh-server-2.1.1p1-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssl-0.9.5a-1cl.i386.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/openssl-devel-0.9.5a-1cl.i386.rpm
DIRECT LINK TO THE SOURCE PACKAGE
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/SRPMS/openssh-2.1.1p1-1cl.src.rpm
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/SRPMS/openssl-0.9.5a-1cl.src.rpm
FreeBSD:
Versions of FreeBSD 4 and 5, released after June 11, 2000 contain a version of OpenSSH that is not vulnerable to this problem. For those users who do not want to download and install the latest version of OpenSSH, a patch has been made available.

参考网址

来源: XF
名称: openssh-uselogin-remote-exec
链接:http://xforce.iss.net/static/4646.php

来源: BID
名称: 1334
链接:http://www.securityfocus.com/bid/1334

来源: OSVDB
名称: 341
链接:http://www.osvdb.org/341

来源: OPENBSD
名称: 20000606 The non-default UseLogin feature in /etc/sshd_config is broken and should not be used.
链接:http://www.openbsd.org/errata.html#uselogin

来源: BUGTRAQ
名称: 20000609 OpenSSH’s UseLogin option allows remote access with root privilege.
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享