Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.50815
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2002:040 (openssh)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to openssh
announced via advisory MDKSA-2002:040.

Details of an upcoming OpenSSH vulnerability will be published early
next week. According to the OpenSSH team, this remote vulnerability
cannot be exploited when sshd is running with privilege separation.
The priv separation code is significantly improved in version 3.3 of
OpenSSH which was released on June 21st. Unfortunately, there are some
known problems with this release
compression does not work on all
operating systems and the PAM support has not been completed.

The OpenSSH team encourages everyone to upgrade to version 3.3
immediately and enable privilege separation. This can be enabled by
placing in your /etc/ssh/sshd_config file the following:

UsePrivilegeSeparation yes

The vulnerability that will be disclosed next week is not fixed in
version 3.3 of OpenSSH, however with priv separation enabled, you will
not be vulnerable to it. This is because privilege separation uses a
seperate non-privileged process to handle most of the work, meaning
that any vulnerability in this part of OpenSSH will never lead to a
root compromise. Only access as the non-privileged user restricted in
chroot would be available.

MandrakeSoft encourages all of our users to upgrade to the updated
packages immediately. This update creates a new user and group on the
system named sshd that is used to run the non-privileged processes.

Affected versions: 7.1, 7.2, 8.0, 8.1, 8.2, Corporate Server 1.0.1,
Single Network Firewall 7.2


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2002:040
http://marc.theaimsgroup.com/?l=openssh-unix-dev&m=102495293705094&w=2

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.