PT-2009-1071 · Red Hat+1 · Fedora+2

Tomas Hoger

·

Published

2009-09-30

·

Updated

2017-09-19

·

CVE-2009-2904

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH version 4.3p2 OpenSSH versions 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11
Description The issue allows for the exploitation of a vulnerability in OpenSSH, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be exploited remotely. A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory.
Recommendations For OpenSSH version 4.3p2, update to a newer version to mitigate the risk. For OpenSSH versions 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, consider restricting access to the ChrootDirectory feature until a patch is available. As a temporary workaround, consider disabling the setuid programs that use configuration files within the chroot directory to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07468
BDU:2015-07470
BDU:2015-07473
BDU:2015-07475
BDU:2015-08531
BDU:2015-08532
BDU:2015-08533
BDU:2015-08534
CVE-2009-2904
RHSA-2009:1470
RHSA-2009_1470

Affected Products

Fedora
Openssh
Red Hat