Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Portable OpenSSH GSSAPI Remote Code Execution Vulnerability

Portable OpenSSH is prone to a remote code-execution vulnerability. The issue derives from a race condition in a vulnerable signal handler.

Reportedly, under specific conditions, it is theoretically possible to execute code remotely prior to authentication when GSSAPI authentication is enabled. This has not been confirmed; the chance of a successful exploit of this nature is considered minimal.

On non-Portable OpenSSH implementations, this same race condition can be exploited to cause a pre-authentication denial of service.

This issue occurs when OpenSSH and Portable OpenSSH are configured to accept GSSAPI authentication.







 

Privacy Statement
Copyright 2008, SecurityFocus