OpenSSH < 2.9.9 / 2.9p2 Symbolic Link 'cookies' File Removal

low Nessus Plugin ID 44071
New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it is different from CVSS.

VPR Score: 5.9

Synopsis

Local attackers may be able to delete arbitrary files.

Description

According to the banner, OpenSSH earlier than 2.9.9 / 2.9p2 is running on the remote host. Such versions contain an arbitrary file deletion vulnerability. Due to insecure handling of temporary files, a local attacker can cause sshd to delete any file it can access named 'cookies'.

Solution

Upgrade to OpenSSH 2.9.9 / 2.9p2 or later.

See Also

http://www.openssh.com/txt/release-2.9.9

http://www.openssh.com/txt/release-2.9p2

https://www.openssh.com/security.html

Plugin Details

Severity: Low

ID: 44071

File Name: openssh_29p2.nasl

Version: 1.5

Type: remote

Family: Misc.

Published: 10/4/2011

Updated: 11/15/2018

Dependencies: ssh_detect.nasl

Risk Information

Risk Factor: Low

VPR Score: 5.9

CVSS v2.0

Base Score: 3.3

Temporal Score: 2.4

Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:openbsd:openssh

Exploit Ease: No known exploits are available

Patch Publication Date: 9/26/2001

Vulnerability Publication Date: 6/4/2001

Reference Information

CVE: CVE-2001-0529

BID: 2825