New FreeBSD, NetBSD Security Advisories
Dan writes "FreeBSD has formally announced a security advisory entitled "OpenSSH buffer management error" for the now famous OpenSSH advisory (OpenSSH has released a new version 3.7.1 to address this issue). NetBSD has issued a similar advisory and fix for this issue. NetBSD has released two additional security advisories entitled "Kernel memory disclosure via ibcs2" and "Insufficient argument checking in sysctl(2)"."
If you ever take a look at the patched code for one of these security advisories, you mainly see some special case code stuck in there to patch up the problem. You never see a reconsideration of the problem. I wonder how long it takes to go from a release version through patch after patch until a piece of code is just old and crufty and in need of wholesale replacement.
The first comment on a BSD story wasn't a BSD troll, now that my freinds is news for nerds, stuff that matters.
Does this affect OS X's implementation of SSHD? So far Apple has not released a patch.
...And when they came for me, there was no one left to speak out for me." - Martin Niemoeller (1892-1984)
Given that the default install has ssh turned on, will they change it to "two remote holes" ?
If you look carefully at the bug - at first glance, it lookls like when SSHD faluts out, some extra memory will be wiped with nulls.
Perhaps there's more to this but basically whats is going on
SSHD need more memory.
Memrory counter is added to.
Memeory is allocated.
Repeat (until memory allocation fails)
then...
Because SSHD needs to wipe all it's memory to null so no crpto stuff is left lying around, all the memory pointed to my them memory counter is wiped. But unfortunalty some of that memory doesen't belong to SSHD because the memory allocation failed.
Moneyed corporations, non-working 'poor' and criminal prisoners are turning productive citizens into tax-slaves.
All of the other vendors released similar bulletins... Most of them questioned the validity of this hole, but to be safe, they issued these notes to their customers to update OpenSSH. I know RedHat and Mandrake did.
Phil
This isn't a hole on OpenBSD. According to Theo this can only crash SSHD, not give access.
-sirket
We only come out at night...
congratulations, you just have let your old sshd reread its configuration instead of stopping it and starting the new one.
bash$
The difference is that if they could get even a very limited shell, that would turn all the local exploit bugs into potential remote exploit holes. That is clearly an order of magnitude more dangerous than a simple DOS.
So, I think it makes sense to distinguish between the two cases, though I think just talking about `holes' is silly. Didn't they used to have `remote root exploit' or similar wording in there? Perhaps the PHBs didn't understand.
_O_
.|< The named which can be named is not the true named