SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#655259

OpenSSH allows arbitrary file deletion via symlink redirection of temporary file

Overview

Due to insecure handling of temporary files, some versions of sshd, an encrypted connection program, can delete any file named "cookies" accessible via the computer running sshd.

I. Description

sshd is the server software used to support ssh, a popular encryted connection program. Some versions of OpenSSH fail to handle temporary files in a secure fashion, allowing their removal during an ssh session. This removal may be reflected in the removal of files named "cookies" on the server. Since sshd runs setuid root, ownership and protection of the "cookies" file will be disregarded.

II. Impact

Using this exploit, an attacker may cause loss of data, particularly web location data used in many web sites.

III. Solution

Apply vendor patches; see the Systems Affected section below.

Systems Affected

VendorStatusDate NotifiedDate Updated
CalderaVulnerable9-Aug-2001
ConectivaVulnerable15-Nov-2001
ImmunixVulnerable15-Nov-2001
NetBSDVulnerable31-Jul-2001
OpenBSDVulnerable21-Aug-2001
OpenSSHVulnerable21-Aug-2001

References


http://www.securityfocus.com/bid/2825
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-010.txt.asc
http://www.openbsd.org/errata.html#sshcookie
http://www.linuxsecurity.com/advisories/other_advisory-1666.html
http://www.linuxsecurity.com/advisories/other_advisory-1654.html

Credit

This vulnerability was initially reported on the Bugtraq discussion list.

This document was last modified by Tim Shimeall.

Other Information

Date Public:2001-06-12
Date First Published:2001-08-21
Date Last Updated:2001-11-15
CERT Advisory: 
CVE-ID(s):CAN-2001-0529
NVD-ID(s):CAN-2001-0529
US-CERT Technical Alerts: 
Metric:0.76
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader