漏洞信息详情
OpenSSH Kerberos任意特权提升漏洞
- CNNVD编号:CNNVD-200112-161
- 危害等级: 高危
- CVE编号:
CVE-2001-1507
- 漏洞类型:
未知
- 发布时间:
2001-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
openbsd - 漏洞来源:
This vulnerability… -
漏洞简介
OpenSSH 3.0.1之前版本存在漏洞。当Kerberos V有效时,该软件不能正确的验证用户,远程攻击者利用该漏洞导致登录受到挑战。
漏洞公告
The vendor has made upgrades available.
OpenSSH packages for Trustix Secure Linux do not have Kerberos support enabled. However, fixes have been provided for those users who wish to enable Kerberos support.
OpenBSD OpenSSH 3.0
-
OpenBSD OpenSSH 3.0.1
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-3.0.1.tgz -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-3.1.0p1-3tr
.i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-3.1.0p1-3tr
.i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-3.1.0p1-3tr
.i586.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpmSource RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/SRPMS/openssh-3.1.0p1-3t
r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpmSource RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/SRPMS/openssh-3.1.0p1-3t
r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpmSource RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/SRPMS/openssh-3.1.0p1-3t
r.src.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-clients-3.1
.0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-clients-3.1
.0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-clients-3.1
.0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-server-3.1.
0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-server-3.1.
0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-server-3.1.
0p1-3tr.i586.rpm
OpenBSD OpenSSH 3.0 p1
-
OpenBSD OpenSSH 3.0.1p1
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.0.1p1.tar
.gz -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-3.1.0p1-3tr
.i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-3.1.0p1-3tr
.i586.rpm -
Trustix openssh-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-3.1.0p1-3tr
.i586.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpmSource RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/SRPMS/openssh-3.1.0p1-3t
r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpmSource RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/SRPMS/openssh-3.1.0p1-3t
r.src.rpm -
Trustix openssh-3.1.0p1-3tr.src.rpmSource RPM.
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/SRPMS/openssh-3.1.0p1-3t
r.src.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-clients-3.1
.0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-clients-3.1
.0p1-3tr.i586.rpm -
Trustix openssh-clients-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-clients-3.1
.0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssh-server-3.1.
0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssh-server-3.1.
0p1-3tr.i586.rpm -
Trustix openssh-server-3.1.0p1-3tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssh-server-3.1.
0p1-3tr.i586.rpm
参考网址
来源: www.openbsd.org
链接:http://www.openbsd.org/errata30.html#sshd
来源: XF
名称: openssh-kerberos-elevate-privileges(7598)
链接:http://www.iss.net/security_center/static/7598.php
来源: BUGTRAQ
名称: 20011119 OpenSSH 3.0.1 (fwd)
链接:http://msgs.securepoint.com/cgi-bin/get/bugtraq0111/114.html
来源: BID
名称: 3560
链接:http://www.securityfocus.com/bid/3560
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END