bug in ssh-vulnkey - ref USN-612-2

Bug #230344 reported by Peter Dobcsanyi
254
Affects Status Importance Assigned to Milestone
openssh-blacklist (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: openssh-blacklist

The "ssh-vulnkey" program doesn't correctly parse "authorized_keys"
files resulting in missing compromised keys. This bug manifests itself
when the option field has parameters containing space. Some options,
most importantly "command", can contain space in quoted strings.

Here is an example showing two lines of an "authorized_keys" file
with the same compromised key:

command="hg-ssh ~/repos/ddb",no-port-forwarding,no-X11-forwarding,no-agent-forwarding ssh-rsa AAAAB3NzaC1yc2EAAAABIwAA...
no-port-forwarding,no-X11-forwarding,no-agent-forwarding ssh-rsa AAAAB3NzaC1yc2EAAAABIwAA...

Only the second line reported as compromised.

The option field is frequently used to (fine) control access to sshd
hosts, so this bug seriously undermines the usefulness of "ssh-vulnkey".

      Peter

Revision history for this message
Peter Dobcsanyi (peter-d) wrote : Re: [Bug 230344] Re: bug in ssh-vulnkey - ref USN-612-2

On Wed, May 14, 2008 at 04:03:01PM -0000, Kees Cook wrote:
> *** This bug is a duplicate of bug 230029 ***
> https://bugs.launchpad.net/bugs/230029
>
> ** This bug has been marked a duplicate of bug 230029
> ssh-vulnkey overlooks keys which have options in authorized_keys

Great, I am happy that it has also been fixed.

However, this the second time that this "duplication" happened to me and
I DID check before posting whether there was anything already reported
about the problem. I used launchpad search facility to find related
reports and nothing came up. Now I am wondering why, is there a delay,
am I doing something wrong?

    Peter

Revision history for this message
Matt Zimmerman (mdz) wrote :

On Thu, May 15, 2008 at 12:10:51AM -0000, Peter Dobcsanyi wrote:
> Great, I am happy that it has also been fixed.
>
> However, this the second time that this "duplication" happened to me and
> I DID check before posting whether there was anything already reported
> about the problem. I used launchpad search facility to find related
> reports and nothing came up. Now I am wondering why, is there a delay,
> am I doing something wrong?

There is not a delay before new bugs are visible, no. If you have a
question about your use of the Launchpad search facility, please file it
here so that someone knowledgeable can respond:

https://answers.edge.launchpad.net/launchpad

--
 - mdz

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.