OpenPKG Security Advisory
OpenPKG-SA-2006.022
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.022
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.022
Advisory Published: 2008-11-19 13:05 UTC
Issue Id (internal): OpenPKG-SI-20061001.01
Issue First Created: 2006-10-01
Issue Last Modified: 2006-12-07
Issue Revision: 08
Subject Name: OpenSSH
Subject Summary: Secure Shell (SSH)
Subject Home: http://www.openssh.com/
Subject Versions: * <= 4.3p2
Vulnerability Id: CVE-2006-4924, CVE-2006-4925, CVE-2006-5051
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector:
Attack Impact: denial of service
Description:
According to a vendor security advisory [0], multiple vulnerabilities
exist in the Secure Shell (SSH) implementation OpenSSH [1]:
First, a pre-authentication denial of service was found by Tavis
Ormandy that would cause sshd(8) to spin until the login grace time
expired. CVE-2006-4924, CVE-2006-4925
Second, an unsafe signal handler, reported by Mark Dowd, was fixed.
The signal handler was vulnerable to a race condition that could be
exploited to perform a pre-authentication denial of service. This
vulnerability could theoretically lead to pre-authentication remote
code execution if some authentication methods like GSSAPI are enabled,
but the likelihood of successful exploitation appears remote.
CVE-2006-5051
References:
[0] http://www.openssh.com/txt/release-4.4
[1] http://www.openssh.com/
Primary Package Name: openssh
Primary Package Home: http://openpkg.org/go/package/openssh
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2.5-SOLID openssh-4.2p1-2.5.3
OpenPKG Community 2-STABLE-20060622 openssh-4.3p2-2.20060622
OpenPKG Community CURRENT openssh-4.3p2-20060924
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2.5-SOLID openssh-4.2p1-2.5.4
OpenPKG Community 2-STABLE-20060622 openssh-4.4p1-2.20060929
OpenPKG Community CURRENT openssh-4.4p1-20060928