HZRN.COM
welcome to my space
X
Welcome to:hzrn.com
Search:  
NAVIGATION: Home >>
CERT Warns of SSH Vulnerabilities
Published by: anonym 2008-11-21

The CERT Coordination Center has issued a warning that vulnerabilities in multiple implementations of SSH (define) could allow hackers to execute arbitrary code with the privileges of the secure SSH process or cause a denial of service.

A CERT/CC security alert said implementations of the SSH transport layer protocol contained vulnerabilities that affect SSH clients and servers and occur before user authentication takes place.

Vulnerable vendors include F-Secure, Intersoft International and Pragma Systems but CERT said the popular OpenSSH and IBM implementations were not exploitable via these attacks.

CERT Advisory CA-2002-07 Double Free Bug in zlib Compression Library::
Any one of these applications may contain vulnerabilities that are warns about any attempt to exploit the vulnerability described in the CERT/CC advisory.
http://www.cert.org/advisories/CA-2002-07.html
HOME

SSH is a program used to log into another computer over a network, to execute commands in a remote machine and to move files from one machine to another. It provides authentication and secure communications over insecure channels and is widely-used as a replacement for rlogin, rsh, rcp, and rdist.

CERT said security consultants Rapid7 ran a suite of test cases, dubbed SSHredder, that examined the connection initialization, key exchange and negotiation phase of the SSH transport layer protocol and found the multiple bugs in different vendors' SSH products. "These vulnerabilities include buffer overflows, and they occur before any user authentication takes place," the Center warned.

In severe cases, CERT warned that remote attackers could execute arbitrary code with the privileges of the SSH process. "Both SSH servers and clients are affected, since both implement the SSH transport layer protocol. On Microsoft Windows systems, SSH servers commonly run with SYSTEM privileges, and on UNIX systems, SSH daemons typically run with root privileges," it added.

In the case of SSH clients, any attacker-supplied code would run with the privileges of the user who started the client program, with the possible exception of SSH clients that may be configured with an effective user ID of root (setuid root), according to the advisory. "Attackers could also crash a vulnerable SSH process, causing a denial-of-service (define:dos_attack>.

The Center urged users to apply the appropriate vendor patches or restrict access to SSH servers to trusted hosts and networks using firewalls or other packet-filtering systems.

"While these workarounds will not prevent exploitation of these vulnerabilities, they will make attacks somewhat more difficult, in part by limiting the number of potential sources of attacks," CERT said.


OASIS Converges on Translation, Localization
Metrowerks Unveils Palm OS 5 Toolset

You are looking at:hzrn.com's CERT Warns of SSH Vulnerabilities, click hzrn.com to home
  • reccomended camera
  • off camera remote flash
  • canon s new ef 800mm f 5 6l is usm
  • need advice on sharpening adjustments
  • how to clean the ccd
  • some pictures i ve taken as well as my flickr
  • help on focusing at a distance
  • dark shadows behind bottom of ears
  • how can i get this picture better
  • when to bounce
  • using the flash for lighting without camera
  • prime vs zoom vs single focal length
  • just starting need advice
  • general focusing questions and 24 105

  • another beginner new to this forum
  • black white movie glasses
  • your st patrick s day experiences
  • night shots
  • i am in dilema help please
  • new to film photography
  • st patrick parade
  • composition basics
  • newbie needs help with these shots
  • 2nd try
  • completely new and don t know where to start
  • designing a website
  • lens cleaning cloth solution
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about CERT Warns of SSH Vulnerabilities , Please add it free.
    About us |Contact us |Advertisement |Site map |Exchange links
    Copyright© 2008hzrn.com All Rights Reserved