LWN.net Logo

openssh: log file corruption

Package(s):openssh CVE #(s):CVE-2007-3102
Created:November 15, 2007 Updated:November 20, 2007
Description: The ssh server can incorrectly write account names to the audit subsystem. A remote attacker can inject strings with parts of audit messages in order to corrupt logs. This can mislead administrators and confuse log parsing tools.
Alerts:
Red Hat RHSA-2007:0703-02 2007-11-15
Red Hat RHSA-2007:0737-02 2007-11-15

(Log in to post comments)

openssh: log file corruption

Posted Dec 10, 2007 20:46 UTC (Mon) by kreutzm (subscriber, #4700) [Link]

"This is a redhat/fedora specific issue"

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds