Re: Upcoming OpenSSH Remote Exploit

From: Bernd Eckenfels (ecki-news2002-06@lina.inka.de)
Date: 06/27/02


From: Bernd Eckenfels <ecki-news2002-06@lina.inka.de>
Date: 27 Jun 2002 03:07:33 GMT

Juergen P. Meier <news@jors.net> wrote:
> PrivSep has apparently nothing to do with this whatsoever.

Privsep does limit the impact (no remote root exploit)

> So the Fix would be to eigther disable these two options or to upgrade
> to OpenSSH 3.4, which has just been released on http://www.openssh.org/

According to the Advisory it is not enough to only turn the options off,
because there are more problems in the 3.4 patch solved which could be also
exploited:

At least PAMAuthenticationViaKbdInt needs to be disabled, too. (openssh
advisory)

openssh.org:
The 3.4 release contain many other fixes done over a week long audit started
when this issue came to light. We believe that some of those fixes are
likely to be important security fixes. Therefore, we urge an upgrade to 3.4.

> Disable ChallengeResponseAuthentication in sshd-config when running
> non-BSD Unix systems (Linux, Solaris, HP/UX...) and be fine.

nope

Greetings
Bernd



Relevant Pages

  • Re: Upcoming OpenSSH Remote Exploit
    ... > PrivSep has apparently nothing to do with this whatsoever. ... According to the Advisory it is not enough to only turn the options off, ... The 3.4 release contain many other fixes done over a week long audit started ... we urge an upgrade to 3.4. ...
    (comp.security.unix)
  • Re: Hogwash
    ... The privsep features do not exist in this version, ... All you've said is that everybody should upgrade now or turn it off. ... new feature in the cutting edge version of OpenSSH. ...
    (FreeBSD-Security)
  • RE: Hogwash
    ... > code if you want to, without privsep. ... There is no guarantee that an upgrade to privsep is going to help, ... unlike most of the openssh codebase. ... and handle this issue in a professional manner. ...
    (FreeBSD-Security)
  • Re: Hogwash
    ... Some of you guys are saying you won't upgrade to privsep as in 3.3 or ... and you won't turn sshd off either. ... without privsep. ...
    (FreeBSD-Security)