Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

OpenSSH 7.0 Fixes Authentication Vulnerability, Other Security Bugs

The developers of OpenSSH announced on Tuesday the availability of version 7.0. The latest release includes new features, security and bug fixes, and cryptography improvements.

The developers of OpenSSH announced on Tuesday the availability of version 7.0. The latest release includes new features, security and bug fixes, and cryptography improvements.

OpenSSH is the OpenBSD Project’s free and open source implementation of the Secure Shell (SSH) cryptographic network protocol 2.0. It provides traffic encryption, secure tunneling capabilities, and authentication methods. OpenSSH is one of the projects for which the Linux Foundation’s Core Infrastructure Initiative (CII) has committed financial support.

According to developers, OpenSSH 7.0 primarily focuses on deprecating weak, legacy and unsafe cryptography. In future releases, OpenSSH plans on disabling MD5-based HMAC algorithms, banning the use of RSA keys smaller than 1024 bits, and disabling several ciphers.

OpenSSH 7.0 addresses a total of four vulnerabilities. One of these flaws is an issue related to the keyboard-interactive authentication mechanism and it exposes servers to brute-force attacks (CVE-2015-5600). The security hole, disclosed in July by a researcher known as KingCope, allows a remote attacker to try out as many as 10,000 different passwords. The attacker would only be limited by a “login grace time” setting that is set by default to two minutes.

Two other vulnerabilities, affecting only the portable version of OpenSSH, were reported by Moritz Jodeit. One of the security holes, a privilege separation flaw related to PAM support, allows an attacker to impersonate other users. However, the attack only works if the attacker has valid credentials and can compromise the pre-authentication process for remote code execution.

The other flaw identified by Jodeit is a use-after-free that is also related to PAM support. This vulnerability can also only be exploited by an attacker who can compromise the pre-authentication process and remotely execute arbitrary code.

Nikolay Edigaryev discovered that the previous two versions of OpenSSH incorrectly set TTYs to be world-writable. This allows a local attacker to write messages to authenticated users, including terminal escape sequences.

Additional details on the new features, bug fixes, and crypto improvements are available in the release notes.

Advertisement. Scroll to continue reading.
Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.