HZGN.COM
welcome to my space
X
Search:  
Welcome to:hzgn.com
NAVIGATION: Home >>
CERT Issues Warning for OpenSSH Flaw
Published by: jack 2008-11-20

CERTŪ Advisories::
issues two certificates to an individual fraudulently claiming to be an employee A flaw exists in Netscape Navigator that could allow an attacker to masquerade
http://www.cert.org/advisories
HOME
The CERT Coordination Center has issued a security alert for a buffer management vulnerability in versions of the OpenBSD Project's popular OpenSSH network connectivity tool.

advisory Resources | ZDNet::
Intel ships BIOS fix for Rutkowskas Black Hat flaw Computer Emergency Readiness Team CERT has issued a warning for what it calls
http://updates.zdnet.com/tags/advisory.html
HOME
Earthweb News: Realtime News for IT Managers::
09, 2003] The software giant issues warning for three vulnerabilities in the CERT Reports Flaws in Compaq GUI. PGP Plug-in Flaw Leaves Encryption Vulnerable
http://news.earthweb.com/index.php/11211
HOME

The security hole, which affects all versions of OpenSSH prior to 3.7, could cause a denial-of-service condition and may also allow an attacker to execute arbitrary code, CERT/CC warned. Systems that use or derive code from vulnerable versions of OpenSSH are also vulnerable.

According to the advisory, the vulnerability exists in the buffer management code of OpenSSH. "The error occurs when a buffer is allocated for a large packet. When the buffer is cleared, an improperly sized chunk of memory is filled with zeros," CERT/CC explained.

OpenSSH, which is included in Linux and Unix OS distributions, is a free version of the SSH (define) tool. It is a popular replacement for Telnet, rlogin, rsh, and ftp protocols.

While the full impact of the OpenSSH vulnerability remains unclear, CERT/CC cautioned that the most likely result would be "heap corruption," which could lead to a denial-of-service (define).

"If it is possible for an attacker to execute arbitrary code, then they may be able to so with the privileges of the user running the sshd process, typically root. This impact may be limited on systems using the privilege separation (privsep) feature available in OpenSSH," it added.

Sysadmins are urged to upgrade to OpenSSH 3.7 or apply available vendor patches. OpenSSH has also issued a fix (available here).

As a temporary workaround, IT admins running vulnerable OpenSSH versions may be able to reduce the impact of the security hole by enabling the "UsePrivilegeSeparation" configuration option in their sshd configuration file. However, CERT/CC warned that the workaround does not prevent exploitation of the vulnerability.

"System administrators are encouraged to carefully review the implications of using the workaround in their environment and use a more comprehensive solution if one is available. The use of privilege separation to limit the impact of future vulnerabilities is encouraged," the Center added.




Intel Gets Extreme
Home Sweet 'Pentium Extreme' Home
PRINT Add to favorites
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about CERT Issues Warning for OpenSSH Flaw , Please add it free.
  • can 039 t get out of bed
  • need expert advice from someone in the field for emotions
  • do you like my poem that i wrote about valium
  • doctor has prescribed prozac but i am too scared to take it
  • do you have some advice with stopping psychotrophic medication
  • why am i so pissed off i have more than i wanted
  • ho wlong does it take to recover from psychotic depression completly thanks its 6monthsfrom medication here
  • alcoholic what can i do
  • what can i do to relieve stress
  • what is a good way to become less depressed
  • i told my parents about my eating disorder
  • i 039 m really fed up come someone help me
  • could i possibly lose my job b c of depression
  • how would a psychiatrist treat or teach one to cope with hearing voices
  • help please
  • could i have a sleeping disorder
  • how do i rid myself of energy vampires without there being a huge ordeal
  • ex world of warcraft addict of 2 years gah why is depression so harsh
  • don 039 t you think life is cruel
  • what do you want to do before you die
  • can i be a p e teacher with adhd
  • hypocondiac please help
  • how are u are u fine
  • do you think suicide is wrong
  • what is the best antidepressant antianxiety medication only tell me from your experience please
  • have a q about panick attacks and anxiety anyone get to the point that they feel so lightheaded and passout
  • help i have a bad addiction to shopping
  • About us |Contact us |Advertisement |Site map |Exchange links
    Copyright© 2008hzgn.com All Rights Reserved