Re: Firewall your ssh status port

Jan Willamowius <[email protected]> Tue, 7 Feb 2017 09:30:14 +0100
Newsgroups gmane.comp.telephony.openh323gk.user
Organization GNU Gatekeeper Project
Message-ID <[email protected]>
I think I still owe you the details on this one:

All GnuGk versions prior to 4.4 can be crashed by remotely opening and
closing multiple ssh connections to the status port (even without
having the ssh credentials). As far as I can tell, this "only" results
in a denial of service and no remote code execution is possible.

So, if you use ssh on the status port, please make sure to update to
GnuGk to 4.4.

Regards,
Jan

-- =

Jan Willamowius, Founder of the GNU Gatekeeper Project
EMail  : [email protected]
Website: https://www.gnugk.org
Support: https://www.willamowius.com/gnugk-support.html

Relaxed Communications GmbH
Frahmredder 91
22393 Hamburg
Gesch=E4ftsf=FChrer: Jan Willamowius
HRB 125261 (Amtsgericht Hamburg)
USt-IdNr: DE286003584


Jan Willamowius wrote:
> Hi,
> =

> users who have enabled ssh on the status port should block access to
> the status port in their firewall or upgrade to the CVS version as soon
> as possible.
> =

> More details later.
> =

> Regards,
> Jan

---------------------------------------------------------------------------=
---
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________________

Posting: mailto:[email protected]
Archive: http://sourceforge.net/mailarchive/forum.php?forum_name=3Dopenh323=
gk-users
Unsubscribe: http://lists.sourceforge.net/lists/listinfo/openh323gk-users
Homepage: http://www.gnugk.org/