SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (VPN)  >   OpenSSH Vendors:   OpenSSH.org
(HP Issues Fix for HP-UX) OpenSSH May Unexpectedly Activate GatewayPorts and Also May Disclose GSSAPI Credentials in Certain Cases
SecurityTracker Alert ID:  1016240
SecurityTracker URL:  http://securitytracker.com/id/1016240
CVE Reference:   CVE-2005-2797, CVE-2005-2798   (Links to External Site)
Date:  Jun 7 2006
Impact:   Disclosure of authentication information, Host/resource access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 4.2
Description:   Two vulnerabilities were reported in OpenSSH. GatewayPorts may be unexpectedly activated. GSSAPI authentication credentials may be disclosed to untrusted remote users.

If no listen address is specified for dynamic port forwardings (forwarding with the '-D' flag), GatewayPorts may be incorrectly activated. As a result, a remote user may be able to access ports on the target system. This flaw was introduced in OpenSSH version 4.0.

GSSAPI credentials can be delegated to users that can request to login with authentication methods other than GSSAPI authentication. As a result, credentials may be inadvertently exposed to untrusted remote users in certain situations.

Impact:   GatewayPorts may be unexpectedly activated.

GSSAPI authentication credentials may be disclosed to untrusted remote users.

Solution:   HP has issued a fix for HP-UX Secure Shell (T1471AA) for the CVE-2005-2798 vulnerability, available at:

http://software.hp.com

HP-UX B.11.00 - HP-UX Secure Shell A.04.20.004
HP-UX B.11.04 - PHSS_34566 or PHSS_34567
HP-UX B.11.11 - HP-UX Secure Shell A.04.20.004
HP-UX B.11.23 - HP-UX Secure Shell A.04.20.005

The HP advisory is available at:

http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00589050

Vendor URL:  www.openssh.org/ (Links to External Site)
Cause:   Access control error
Underlying OS:  UNIX (HP/UX)
Underlying OS Comments:  B.11.00, B.11.04, B.11.11, B.11.23

Message History:   This archive entry is a follow-up to the message listed below.
Sep 2 2005 OpenSSH May Unexpectedly Activate GatewayPorts and Also May Disclose GSSAPI Credentials in Certain Cases



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, SecurityGlobal.net LLC