CERT releases advisory regarding the buffer overflows in SSH Daemon
15 Dec. 1999
Summary
As we reported in our earlier article: SSH 1.2.27 is vulnerable to a remote buffer overflow (RSAREF), the older implementation of SSH contained a security vulnerability that allows remote attackers to exploit an internal buffer overflow of the SSH daemon to cause it to execute arbitrary code, causing a system compromise. CERT has now released a full disclosure of this vulnerability including a detailed text on what administrators should do.
Using the two vulnerabilities in conjunction allows an intruder to execute arbitrary code with the privileges of the process running sshd - typically root.