|
|
|
![]() |
Vulnerability Note VU#797027OpenSSH does not initialize PAM session thereby allowing PAM restrictions to be bypassedOverviewOpenSSH is an implementation of the Secure Shell (SSH) protocol. It can be configured to use Linux Pluggable Authentication Modules (PAM) for added authentication. A vulnerability exists in OpenSSH, and perhaps other implementations of SSH, which can allow to potentially bypass PAM restrictions.I. DescriptionOpenSSH fails to call pam_open_session if no pty (pseudo-terminal driver) is used. This in turn does not activate the security modules specified in /etc/pam.d. It has been pointed out that if you use pam_limits.so to set resource limits, then users could bypass these limits by calling ssh in this manner.II. ImpactAn attacker can bypass the PAM security modules specified on the target machine.III. SolutionUpgrade to OpenSSH 2.9.9p1.Restrict access to the SSH service
Referenceshttp://www.securityfocus.com/bid/2917 Christian Kraemer discovered this vulnerability. This document was written by Jason Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||