Mailing List Archive

[Bug 3196] New: [Information Disclosure] OpenSSH_7.4p1 Raspbian-10+deb9u7 discloses OS version

Bug ID: 3196
Summary: [Information Disclosure] OpenSSH_7.4p1
Raspbian-10+deb9u7 discloses OS version
Product: Portable OpenSSH
Version: 7.4p1
Hardware: Other
OS: Other
Status: NEW
Severity: security
Priority: P5
Component: sshd

Created attachment 3432
CrackMapExec accidentally reports OS version using the paramiko library

The Raspbian-10+deb9u7 release of OpenSSH_7.4p1 sends over the
"Raspbian-10+deb9u7" text when communicating SSHD version to a client.
This is considered an Information Disclosure error, because SSHD
shouldn't disclose OS Version information to clients.

REPLICATE: Run CrackMapExec against OpenSSH_7.4p1 Raspbian-10+deb9u7
with a command like the following:

./cme --verbose ssh -u pi --port 2322
CrackMapExec( uses the paramiko
library( to dectect SSH version.

If you traceback the output of CME, you'll find that it's just paramiko
"reading a line from the socket" and parsing it to get the version

You are receiving this mail because:
You are watching the assignee of the bug.
openssh-bugs mailing list