OSVDB ID: 29264

Title: OpenSSH Signal Handler Pre-authentication Race Condition Code Execution

Info

Disclosure

Sep 28, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

OpenSSH (portable) contains a flaw that may allow a remote attacker to execute arbitrary code under some circumstances. When configured with GSSAPI authentication, the signal handler is prone to a race condition that could be exploited to conduct a Denial of Service and possibly execute arbitrary code. No further details have been provided. Note: On OpenSSH, this vulnerability can only be leveraged for a remote Denial of Service. The conditions for remote exploitation to execute arbitrary code are considered to be unlikely.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service
Impact: Loss of Integrity, Loss of Availability
Exploit: Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to version 4.4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

OpenSSH

OpenSSH

4.3

References

Credit

  • Mark Dowd - Avertavertlabs.com - McAfee Avert(tm) Labs


Direct URL: http://osvdb.org/29264