PT-2009-1071 · Red Hat+1 · Fedora+2
Tomas Hoger
·
Published
2009-09-30
·
Updated
2017-09-19
·
CVE-2009-2904
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenSSH version 4.3p2
OpenSSH versions 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11
Description
The issue allows for the exploitation of a vulnerability in OpenSSH, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be exploited remotely. A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory.
Recommendations
For OpenSSH version 4.3p2, update to a newer version to mitigate the risk.
For OpenSSH versions 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, consider restricting access to the ChrootDirectory feature until a patch is available.
As a temporary workaround, consider disabling the setuid programs that use configuration files within the chroot directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fedora
Openssh
Red Hat