|
A remote overflow exists in OpenSSH with SSHv2 challenge-response authentication. OpenSSH fails to correctly check integer boundaries in the challenge-response authentication when OpenSSH is using SKEY or BSD_AUTH authentication, resulting in an integer overflow. With a specially crafted request, an attacker can cause the sshd daemon to execute arbitrary code on this host, resulting in a loss of confidentiality, integrity, and/or availability.
|