| Vulnerability Name: | CVE-2013-4548 (CCN-88624) | ||||||||||||||||||||||||
| Assigned: | 2013-11-08 | ||||||||||||||||||||||||
| Published: | 2013-11-08 | ||||||||||||||||||||||||
| Updated: | 2019-10-09 | ||||||||||||||||||||||||
| Summary: | The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||
| References: | Source: CCN Type: IBM SECURITY ADVISORY AIX OpenSSH Vulnerability Source: MITRE Type: CNA CVE-2013-4548 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1726 Source: HP Type: UNKNOWN SSRT101487 Source: MLIST Type: UNKNOWN [oss-security] 20131107 Re: CVE Request - OpenSSH Source: CCN Type: SA55594 OpenSSH AES-GCM Ciphers Privilege Escalation Vulnerability Source: CCN Type: OpenSSH Web site gcmrekey.adv Source: CONFIRM Type: Vendor Advisory http://www.openssh.com/txt/gcmrekey.adv Source: CCN Type: OSVDB ID: 99551 OpenSSH sshd Process AES-GCM Cipher Handling Message Authentication Code (MAC) Initialization Failure Uninitialized Callback Pointer Usage Privilege Escalation Source: CCN Type: BID-63605 OpenSSH 'sshd' Process Remote Memory Corruption Vulnerability Source: UBUNTU Type: UNKNOWN USN-2014-1 Source: XF Type: UNKNOWN openssh-cve20134548-priv-esc(88624) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4548 | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||