Re: OpenSSH-portable <= 3.6.1p1 bug?

From: Peter C. Lai (sirmoo_at_cowbert.2y.net)
Date: 05/13/03

  • Next message: Colin Percival: "Re: xdelta files for security patches"
    Date: Tue, 13 May 2003 15:05:19 -0400
    To: Omar Lopez <magura@ardilla.dyndns.org>
    
    

    I think this explains it pretty well: (it's under section 3. of the advisory
    you posted).

    <blockquote>
    NOTE. FreeBSD uses both a different PAM implementation and a different PAM
    support in OpenSSH: it doesn't seem to be vulnerable to this particular timing
    leak issue.

    All OpenSSH-portable releases <= OpenSSH_3.6.1p1 compiled with PAM support
    enabled (./configure --with-pam) are vulnerable to this information leak. The
    PAMAuthenticationViaKbdInt directive doesn't need to be enabled in sshd_config.
    </blockquote>

    Howevever, it lists MACOSX as "unconfirmed". I thought MACOSX used
    the FreeBSD ssh implementation.

    On Mon, May 12, 2003 at 11:31:03PM +0200, Omar Lopez wrote:
    > Hi:
    > I Read these security advisory.
    > http://lab.mediaservice.net/advisory/2003-01-openssh.txt
    > Is my FreeBSD 5.0 afected? What other versions are afected?
    >
    > Thanks.
    >

    -- 
    Peter C. Lai
    University of Connecticut
    Dept. of Molecular and Cell Biology
    Yale University School of Medicine
    SenseLab | Research Assistant
    http://cowbert.2y.net/
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Colin Percival: "Re: xdelta files for security patches"

    Relevant Pages

    • RE: FreeBSD Security Advisory FreeBSD-SA-06:23.openssl
      ... The description of CVE-2006-3738 in the advisory from openssl.org ... Subject: FreeBSD Security Advisory FreeBSD-SA-06:23.openssl ... FreeBSD includes software from the OpenSSL Project. ... Applications which perform public key operations using untrusted keys may be ...
      (FreeBSD-Security)
    • FreeBSD Security Advisory FreeBSD-SA-05:18.zlib
      ... For general information regarding FreeBSD Security Advisories, ... including descriptions of the fields above, security branches, and the ... The issue discussed in this advisory is distinct from the ... A fixed-size buffer is used in the decompression of data streams. ...
      (FreeBSD-Security)
    • [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-05:18.zlib
      ... For general information regarding FreeBSD Security Advisories, ... including descriptions of the fields above, security branches, and the ... The issue discussed in this advisory is distinct from the ... A fixed-size buffer is used in the decompression of data streams. ...
      (freebsd-announce)
    • FreeBSD Security Advisory FreeBSD-SA-05:18.zlib
      ... For general information regarding FreeBSD Security Advisories, ... including descriptions of the fields above, security branches, and the ... The issue discussed in this advisory is distinct from the ... A fixed-size buffer is used in the decompression of data streams. ...
      (Bugtraq)
    • Buffer overflow in /usr/games/strfile
      ... Below is an advisory for a vulnerable buffer in the /usr/games/strfile binary ... FreeBSD /usr/games/strfile buffer overflow ... FreeBSD /usr/games/strfile contains a vulnerable buffer which can ...
      (FreeBSD-Security)