Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | |||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.10954 |
Kategorie: | Gain a shell remotely |
Titel: | OpenSSH AFS/Kerberos ticket/token passing |
Zusammenfassung: | The remote host is running a version of OpenSSH older than 3.2.1; which is prone to a buffer overflow vulnerability. |
Beschreibung: | Summary: The remote host is running a version of OpenSSH older than 3.2.1 which is prone to a buffer overflow vulnerability. Vulnerability Insight: A buffer overflow exists in the daemon if AFS is enabled on the remote system, or if the options KerberosTgtPassing or AFSTokenPassing are enabled. Even in this scenario, the vulnerability may be avoided by enabling UsePrivilegeSeparation. Affected Software/OS: Versions prior to 2.9.9 are vulnerable to a remote root exploit. Versions prior to 3.2.1 are vulnerable to a local root exploit. Solution: Upgrade to the latest version of OpenSSH CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Querverweis: |
BugTraq ID: 4560 Common Vulnerability Exposure (CVE) ID: CVE-2002-0575 http://www.securityfocus.com/bid/4560 Bugtraq: 20020419 OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable buffer overflow (Google Search) http://online.securityfocus.com/archive/1/268718 Bugtraq: 20020420 OpenSSH Security Advisory (adv.token) (Google Search) http://archives.neohapsis.com/archives/bugtraq/2002-04/0298.html Bugtraq: 20020426 Revised OpenSSH Security Advisory (adv.token) (Google Search) http://online.securityfocus.com/archive/1/269701 Bugtraq: 20020429 TSLSA-2002-0047 - openssh (Google Search) http://archives.neohapsis.com/archives/bugtraq/2002-04/0394.html Bugtraq: 20020517 OpenSSH 3.2.2 released (fwd) (Google Search) http://marc.info/?l=bugtraq&m=102167972421837&w=2 Caldera Security Advisory: CSSA-2002-022.2 ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-022.2.txt http://www.osvdb.org/781 http://marc.info/?l=vuln-dev&m=101924296115863&w=2 http://www.iss.net/security_center/static/8896.php |
Copyright | This script is Copyright (C) 2002 Thomas Reinke |
Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |