Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: Minor OpenSSH/pam vuln (non-exploitable)

Minor OpenSSH/pam vuln (non-exploitable)

From: <das_at_decisionsoft.com>
Date: 13 Nov 2003 12:23:15 -0000
('binary' encoding is not supported, stored as-is) The home page of the one time password system (or otpw -- http://www.cl.cam.ac.uk/~mgk25/otpw.html) has info about how OpenSSH doesn't correctly return PAM_CONV_ERR when a user cancels a login (but instead incorrectly calls pam_end() having the side effect that memory is not correctly scrubbed (or who knows what for other PAM modules). This info comes directly from the aforementioned website.

This has been reported via the appropriate bugzilla (http://bugzilla.mindrot.org/show_bug.cgi?id=632) but not yet fixed.

If there are any hardware security tokens (for example) which might fail to go back to a locked state due to this bug then it might introduce an exploitable vulnerability in that situation. Otherwise, it just fails to provide all the security assurances it should (with respect to scrubbing the ram).

If anyone who knows more about pam and OpenSSH has any further analysis to add, it would be much appreciated.
Received on Nov 13 2003
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]