|
|
|
![]() |
Vulnerability Note VU#209807Portable OpenSSH server PAM conversion stack corruptionOverviewThere is a vulnerability in the Portable OpenSSH server that may corrupt the PAM conversion stack.I. DescriptionThe Portable OpenSSH server contains a vulnerability that may permit an attacker to corrupt the PAM conversion stack. Versions 3.7p1 and 3.7.1p1 are affected. Note that the OpenBSD-specific releases are not affected by this issue.II. ImpactThe complete impact of this vulnerability is not yet known, but may lead to privilege escalation, or a denial of service.III. SolutionOpenSSH has announced version 3.7.1p2 to resolve this issue.This issue can be mitigated by not using PAM. Set "UsePAM no" in sshd_config.
References
Thanks to OpenSSH for reporting this vulnerability. This document was written by Jason A Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||