PT-2007-1056 · Openssh+3 · Openssh+3

Publicado

2007-09-12

·

Atualizado

2024-07-08

·

CVE-2007-4752

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: openssh versions prior to 4.7 openssh-askpass-gnome version 3.9p1 openssh-askpass version 3.9p1 openssh-server version 3.9p1 openssh-clients version 3.9p1
Description: The issue concerns multiple vulnerabilities in the openssh package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The problem arises from improper handling of untrusted cookies, allowing attackers to gain privileges by treating an X client as trusted.
Recommendations: For openssh versions prior to 4.7, update to version 4.7 or later. For openssh-askpass-gnome version 3.9p1, consider disabling the openssh-askpass-gnome function until a patch is available. For openssh-askpass version 3.9p1, restrict access to the openssh-askpass module to minimize the risk of exploitation. For openssh-server version 3.9p1, avoid using the ssh protocol in the affected server until the issue is resolved. For openssh-clients version 3.9p1, consider disabling the openssh-clients function until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-06466
BDU:2015-06468
BDU:2015-06470
BDU:2015-06472
BDU:2015-06474
BDU:2015-08365
BDU:2015-08366
BDU:2015-08367
BDU:2015-08368
BDU:2015-08369
BDU:2015-09602
CVE-2007-4752
DSA-1576-1
HPSBUX02287
OPENSUSE-SU-2024:11124-1
RHSA-2008:0855
RHSA-2008_0855

Produtos afetados

Alt Linux
Hp-Ux
Openssh
Red Hat