(HP Issues Fix for HP-UX) OpenSSH May Unexpectedly Activate GatewayPorts and Also May Disclose GSSAPI Credentials in Certain Cases
|
|
SecurityTracker Alert ID: 1016240 |
|
SecurityTracker URL: http://securitytracker.com/id/1016240
|
|
CVE Reference:
CVE-2005-2797, CVE-2005-2798
(Links to External Site)
|
Date: Jun 7 2006
|
Impact:
Disclosure of authentication information, Host/resource access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to 4.2
|
Description:
Two vulnerabilities were reported in OpenSSH. GatewayPorts may be unexpectedly activated. GSSAPI authentication credentials may be disclosed to untrusted remote users.
If no listen address is specified for dynamic port forwardings (forwarding with the '-D' flag), GatewayPorts may be incorrectly activated. As a result, a remote user may be able to access ports on the target system. This flaw was introduced in OpenSSH version 4.0.
GSSAPI credentials can be delegated to users that can request to login with authentication methods other than GSSAPI authentication. As a result, credentials may be inadvertently exposed to untrusted remote users in certain situations.
|
Impact:
GatewayPorts may be unexpectedly activated.
GSSAPI authentication credentials may be disclosed to untrusted remote users.
|
Solution:
HP has issued a fix for HP-UX Secure Shell (T1471AA) for the CVE-2005-2798 vulnerability, available at:
http://software.hp.com
HP-UX B.11.00 - HP-UX Secure Shell A.04.20.004
HP-UX B.11.04 - PHSS_34566 or PHSS_34567
HP-UX B.11.11 - HP-UX Secure Shell A.04.20.004
HP-UX B.11.23 - HP-UX Secure Shell A.04.20.005
The HP advisory is available at:
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00589050
|
Vendor URL: www.openssh.org/ (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
UNIX (HP/UX)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Wed, 7 Jun 2006 09:14:23 -0400
Subject: HPSBUX02090 SSRT051058 rev.2 - HP-UX Secure Shell Remote Denial of Service (DoS)
|
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00589050
CVE-2005-2096
CVE-2005-2798
|
|