[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] OpenSSH 3.5p1 Remote Root Exploit for FreeBSD
This seems to be in libopie rather than sshd or libpam and happens
when the username is longer than OPIE_PRINCIPAL_MAX. I'm not sure
exactly where inside libopie it is, but commenting out pam_opie.so
seems to prevent it.
prevents usernames longer than OPIE_PRINCIPAL_MAX from being accepted
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.