Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


[openssh-unix-announce] Multiple PAM vulnerabilities in portable OpenSSH
.

  • To: [EMAIL PROTECTED]
  • Subject: [openssh-unix-announce] Multiple PAM vulnerabilities in portable OpenSSH
  • From: Damien Miller <[EMAIL PROTECTED]>
  • Date: Tue, 23 Sep 2003 06:40:25 -0600 (MDT)
  • Cc: [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED]
  • Sender: [EMAIL PROTECTED]
.
 
Subject: Portable OpenSSH Security Advisory: sshpam.adv

This document can be found at:  http://www.openssh.com/txt/sshpam.adv

1. Versions affected:

        Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiple 
        vulnerabilities in the new PAM code. At least one of these bugs 
        is remotely exploitable (under a non-standard configuration, 
        with privsep disabled). 

        The OpenBSD releases of OpenSSH do not contain this code and 
        are not vulnerable. Older versions of portable OpenSSH are not 
        vulnerable.

2. Solution:

        Upgrade to Portable OpenSSH 3.7.1p2 or disable PAM 
        support ("UsePam no" in sshd_config). 

        Due to complexity, inconsistencies in the specification and 
        differences between vendors' PAM implementations we recommend 
        that PAM be left disabled in sshd_config unless there is a need 
        for its use. Sites only using public key or simple password 
        authentication usually have little need to enable PAM support.

_______________________________________________
openssh-unix-announce mailing list
[EMAIL PROTECTED]
http://www.mindrot.org/mailman/listinfo/openssh-unix-announce

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.