Upcoming OpenSSH Remote Exploit

From: Bernd Eckenfels (ecki-news2002-06@lina.inka.de)
Date: 06/25/02


From: Bernd Eckenfels <ecki-news2002-06@lina.inka.de>
Date: 25 Jun 2002 02:21:16 GMT

Hello,

Theo de Raadt is alerting the Vendors that ISS will publish an remote
exploit for OpenSSH and that 3.3p1 is able to limit the scope of the exploit
due to privsep.

Some vendors like Debian have already reacted and new versions of openssh
available, unfortunatelly the new openssh veriosn does not work pretty wel
with kerberos, pam or linux 2.0/2.2

Read all about it here: http://www.eckes.org/article.php?sid=73

Greetings
Bernd

-- 
www.eckes.org - Home of a Geek
www.freefireorg - The Freefire Project - Firewalling with Open Source



Relevant Pages

  • Re: Hogwash
    ... Subject: Upcoming OpenSSH vulnerability ... Depending on what your system is, privsep may break some ssh ... work with your vendor so that we get patches to make it work on your ... You must call on your vendors to help us. ...
    (FreeBSD-Security)
  • Upcoming OpenSSH vulnerability
    ... OpenSSH 3.3p was released a few days ago, ... Depending on what your system is, privsep may break some ssh ... work with your vendor so that we get patches to make it work on your ... You must call on your vendors to help us. ...
    (Bugtraq)
  • Upcoming OpenSSH vulnerability (fwd)
    ... Subject: Upcoming OpenSSH vulnerability ... Depending on what your system is, privsep may break some ssh ... work with your vendor so that we get patches to make it work on your ... You must call on your vendors to help us. ...
    (FreeBSD-Security)
  • [VulnWatch] Upcoming OpenSSH vulnerability
    ... There is an upcoming OpenSSH vulnerability that we're working on with ISS. ... Depending on what your system is, privsep may break some ssh functionality. ... vendors to help us. ... So, if vendors would JUMP and get it working better, and send us patches ...
    (VulnWatch)
  • [openssh-unix-announce] Re: Upcoming OpenSSH vulnerability
    ... > Subject: Upcoming OpenSSH vulnerability ... However, with privsep turned on, you are immune from ... > work with your vendor so that we get patches to make it work on your ... > You must call on your vendors to help us. ...
    (FreeBSD-Security)