hep-cat.de

September 16, 2008

Debian: New openssh packages fix denial of service (CVE-2008-4109)

Filed under: Unauthorized — atari @ 11:27 pm
Debian 4.0 CVE-2008-4109

It has been discovered that the signal handler implementing the login timeout in Debian's version of the OpenSSH server uses functions which are not async-signal-safe, leading to a denial of service vulnerability.

Package:           openssh
Vulnerability:     remote
Problem type:      unsafe signal handler
Debian-specific:   no
CVE Id(s):         CVE-2008-4109
Debian Bug:        498678

Systems affected by this issue suffer from lots of zombie sshd processes. Processes stuck with a "[net]" process title have also been observed. Over time, a sufficient number of processes may accumulate such that further login attempts are impossible. Presence of these processes does not indicate active exploitation of this vulnerability. It is possible to trigger this denial of service condition by accident.

For the stable distribution (etch), this problem has been fixed in version 4.3p2-9etch3.

http://lists.debian.org/debian-security-announce/2008/msg00227.html

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URL

Leave a comment

Powered by WordPress