REDHAT-BUG-2498184: High severity libssh libssh vulnerability
A flaw was found in libssh server-side GSSAPIKeyExchange authorization. In sshpacketuserauthrequest() in src/messages.c, the gssapi-keyex login path granted success after Kerberos authentication without dispatching the callback that verifies whether the authenticated principal is authorized for the requested local user. On servers with GSSAPIKeyExchange enabled, an authenticated client can therefore log in as an arbitrary local user if the missing principal-to-user authorization check is relied upon for access control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2498184?
The severity of REDHAT-BUG-2498184 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2498184?
To fix REDHAT-BUG-2498184, apply the latest security patches for libssh that address this authorization flaw.
What software is affected by REDHAT-BUG-2498184?
The affected software for REDHAT-BUG-2498184 is libssh.
What is the risk level associated with REDHAT-BUG-2498184?
The risk level associated with REDHAT-BUG-2498184 is rated at 33.
What is the description of REDHAT-BUG-2498184?
REDHAT-BUG-2498184 describes a flaw in libssh's server-side GSSAPIKeyExchange authorization that can lead to unauthorized access post-Kerberos authentication.