Contributed by Dengue on from the security dept.
" Insufficient range control calculations (16-bit unsigned variable is used instead of 32-bit, which causes integer overflow) in the detect_attack() function leads to table index overflow bug. This effectively allows an attacker to overwrite arbitrary portions of memory. The altered memory locations affect code that is executed by the daemon with uid 0, and this can be leveraged to obtain general root access to the system."Users are advised to disable SSH1 Support in versions prior to OpenSSH 2.3.0 or upgrade to OpenSSH 2.3.0 (OpenBSD 2.8), or OpenSSH 2.3.2 (available in -current).
(Comments are closed)