漏洞信息详情
OpenSSH基于源的密钥IP访问控制绕过漏洞
- CNNVD编号:CNNVD-200110-098
- 危害等级: 高危
- CVE编号:
CVE-2001-1380
- 漏洞类型:
其他
- 发布时间:
2001-10-18
- 威胁类型:
远程
- 更新时间:
2006-03-28
- 厂 商:
openbsd - 漏洞来源:
Discovery credited… -
漏洞简介
OpenSSH 2.9.9之前版本在使用~/.ssh/authorized_keys2文件中的keypair和多个不同类型的密钥时可能不正确地处理与密钥有关的\”from\”选项,远程攻击者可以从未认证的IP地址登录。
漏洞公告
Upgrades are available.
RedHat openssh-askpass-2.1.1p4-1.i386.rpm
-
Red Hat 7.0 i386 openssh-askpass-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/openssh-askpass-2.9p2-10.7.i38
6.rpm
RedHat openssh-clients-2.1.1p4-1.i386.rpm
-
Red Hat 7.0 i386 openssh-clients-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/openssh-clients-2.9p2-10.7.i38
6.rpm
RedHat openssh-server-2.1.1p4-1.i386.rpm
-
Red Hat 7.0 i386 openssh-server-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/openssh-server-2.9p2-10.7.i386
.rpm
RedHat openssh-2.9p2-7.i386.rpm
-
Red Hat 7.2 i386 openssh-2.9p2-11.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/openssh-2.9p2-11.i386.rpm
RedHat openssh-askpass-gnome-2.9p2-7.i386.rpm
-
Red Hat 7.2 i386 openssh-askpass-gnome-2.9p2-11.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/openssh-askpass-gnome-2.9p2-11
.i386.rpm
RedHat openssh-2.5.2p2-5.i386.rpm
-
Red Hat 7.1 i386 openssh-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/openssh-2.9p2-10.7.i386.rpm
RedHat openssh-askpass-2.9p2-7.i386.rpm
-
Red Hat 7.2 i386 openssh-askpass-2.9p2-11.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/openssh-askpass-2.9p2-11.i386.
rpm
RedHat openssh-2.1.1p4-1.i386.rpm
-
Red Hat 7.0 i386 openssh-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/openssh-2.9p2-10.7.i386.rpm
RedHat openssh-askpass-gnome-2.1.1p4-1.i386.rpm
-
Red Hat 7.0 i386 openssh-askpass-gnome-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/openssh-askpass-gnome-2.9p2-10
.7.i386.rpm
RedHat openssh-server-2.5.2p2-5.i386.rpm
-
Red Hat 7.1 i386 openssh-server-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/openssh-server-2.9p2-10.7.i386
.rpm
RedHat openssh-askpass-gnome-2.5.2p2-5.i386.rpm
-
Red Hat 7.1 i386 openssh-askpass-gnome-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/openssh-askpass-gnome-2.9p2-10
.7.i386.rpm
RedHat openssh-clients-2.9p2-7.i386.rpm
-
Red Hat 7.2 i386 openssh-clients-2.9p2-11.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/openssh-clients-2.9p2-11.i386.
rpm
RedHat openssh-clients-2.5.2p2-5.i386.rpm
-
Red Hat 7.1 i386 openssh-clients-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/openssh-clients-2.9p2-10.7.i38
6.rpm
RedHat openssh-server-2.9p2-7.i386.rpm
-
Red Hat 7.2 i386 openssh-server-2.9p2-11.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/openssh-server-2.9p2-11.i386.r
pm
RedHat openssh-askpass-2.5.2p2-5.i386.rpm
-
Red Hat 7.1 i386 openssh-askpass-2.9p2-10.7.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/openssh-askpass-2.9p2-10.7.i38
6.rpm
OpenSSH OpenSSH 2.5
-
OpenSSH OpenSSH 2.2.9 (OpenBSD)
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-2.9.9.tgz
OpenSSH OpenSSH 2.5.1
-
OpenSSH OpenSSH 2.2.9 (OpenBSD)
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-2.9.9.tgz
OpenSSH OpenSSH 2.5.2
-
OpenSSH OpenSSH 2.2.9 (OpenBSD)
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-2.9.9.tgz
OpenSSH OpenSSH 2.9
-
OpenSSH openssh.key.acl.patch
http://www.securityfocus.com/data/vulnerabilities/patches/openssh.key.
acl.patch -
OpenSSH OpenSSH 2.2.9 (OpenBSD)
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-2.9.9.tgz
OpenSSH OpenSSH 2.9 p2
-
Immunix 7.0 openssh-2.9.9p2-1.0_imnx.i386.rpm
ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/7.0/updates/RPMS
/openssh-2.9.9p2-1.0_imnx.i386.rpm -
Immunix 7.0 openssh-askpass-2.9.9p2-1.0_imnx.i386.rpm
ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/7.0/updates/RPMS
/openssh-askpass-2.9.9p2-1.0_imnx.i386.rpm -
Immunix 7.0 openssh-clients-2.9.9p2-1.0_imnx.i386.rpm
ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/7.0/updates/RPMS
/ -
Immunix 7.0 openssh-server-2.9.9p2-1.0_imnx.i386.rpm
ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/7.0/updates/RPMS
/openssh-server-2.9.9p2-1.0_imnx.i386.rpm -
MandrakeSoft 1.0.1 openssh-2.9.9p2-2.4mdk.i586.rpm
http://www.linux-mandrake.com/en/ftp.php3 -
MandrakeSoft 1.0.1 openssh-askpass-2.9.9p2-2.4mdk.i586.rpm
http://www.linux-mandrake.com/en/ftp.php3 -
MandrakeSoft 1.0.1 openssh-clients-2.9.9p2-2.4mdk.i586.rpm
http://www.linux-mandrake.com/en/ftp.php3 -
MandrakeSoft 1.0.1 openssh-server-2.9.9p2-2.4mdk.i586.rpm
http://www.linux-mandrake.com/en/ftp.php3 -
MandrakeSoft 7.1 openssh-askpass-2.9.9p2-2.4mdk.i586.rpm
http://www.linux-mandrake.com/en/ftp.php3 - MandrakeSoft 7.1 openssh-a
参考网址
来源:US-CERT Vulnerability Note: VU#905795
名称: VU#905795
链接:http://www.kb.cert.org/vuls/id/905795
来源: REDHAT
名称: RHSA-2001:114
链接:http://rhn.redhat.com/errata/RHSA-2001-114.html
来源: BUGTRAQ
名称: 20010926 OpenSSH Security Advisory (adv.option)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=100154541809940&w=2
来源: XF
名称: openssh-access-control-bypass(7179)
链接:http://xforce.iss.net/xforce/xfdb/7179
来源: BID
名称: 3369
链接:http://www.securityfocus.com/bid/3369
来源: OSVDB
名称: 642
链接:http://www.osvdb.org/642
来源: MANDRAKE
名称: MDKSA-2001:081
链接:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-081.php
来源: CIAC
名称: M-010
链接:http://www.ciac.org/ciac/bulletins/m-010.shtml
来源: IMMUNIX
名称: IMNX-2001-70-034-01
链接:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01
来源: CONECTIVA
名称: CLSA-2001:431
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000431