|
Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
Portable OpenSSH is prone to a remote code-execution vulnerability. The issue derives from a race condition in a vulnerable signal handler. Reportedly, under specific conditions, it is theoretically possible to execute code remotely prior to authentication when GSSAPI authentication is enabled. This has not been confirmed; the chance of a successful exploit of this nature is considered minimal. On non-Portable OpenSSH implementations, this same race condition can be exploited to cause a pre-authentication denial of service. This issue occurs when OpenSSH and Portable OpenSSH are configured to accept GSSAPI authentication. |
|
|
Privacy Statement |