Vulnerability CVE-2013-4548: Information

Description

The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.

Severity: MEDIUM (6.0)

Published: Nov. 8, 2013
Modified: Oct. 10, 2019
Error type identifier: CWE-264

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
opensshsisyphus5.9p1-alt79.6p1-alt1ALT-PU-2013-1071-1108153Fixed
opensshp105.9p1-alt77.9p1-alt4.p10.4ALT-PU-2013-1071-1108153Fixed
opensshp95.9p1-alt77.9p1-alt1ALT-PU-2013-1071-1108153Fixed
opensshc10f15.9p1-alt77.9p1-alt4.p10.4ALT-PU-2013-1071-1108153Fixed
opensshc9f25.9p1-alt77.9p1-alt4.p10.4ALT-PU-2013-1071-1108153Fixed
opensshc75.9p1-alt76.7p1-alt1.M70C.5ALT-PU-2014-1369-1117116Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:openbsd:openssh:6.3:*:*:*:*:*:*:*

      cpe:2.3:a:openbsd:openssh:6.2:*:*:*:*:*:*:*