TUCoPS :: BSD :: bsd5367.htm

OpenSSH defect in the BSD_AUTH access control handling
28th May 2002 [SBWID-5367]
COMMAND

	OpenSSH defect in the BSD_AUTH access control handling

SYSTEMS AFFECTED

	OpenSSH 3.2.2

PROBLEM

	Reported as bug \"OpenBSD  PR  2659\",  -  there  is  a  defect  in  the
	BSD_AUTH access control handling for OpenBSD and BSD/OS systems:
	

	Under certain conditions, on systems using  YP  with  netgroups  in  the
	password database, it is possible that sshd  does  ACL  checks  for  the
	requested user name but uses the password database entry of a  different
	user  for  authentication.  This   means   that   denied   users   might
	authenticate successfully while permitted  users  could  be  locked  out
	(OpenBSD PR 2659).

SOLUTION

	Upgrade to OpenSSH 3.2.3

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH