CVE-2001-0361 Information

Description

Implementations of SSH version 1.5 including (1) OpenSSH up to version 2.3.0 (2) AppGate and (3) ssh-1 up to version 1.2.31 in certain configurations allow a remote attacker to decrypt and/or alter traffic via a \Bleichenbacher attack\ on PKCS1 version 1.5.

Reference

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc http://marc.info/?l=bugtraq&m=98158450021686&w=2 http://www.ciac.org/ciac/bulletins/l-047.shtml http://www.debian.org/security/2001/dsa-023 http://www.debian.org/security/2001/dsa-027 http://www.debian.org/security/2001/dsa-086 http://www.novell.com/linux/security/advisories/adv004_ssh.html http://www.osvdb.org/2116 http://www.securityfocus.com/bid/2344 https://exchange.xforce.ibmcloud.com/vulnerabilities/6082

Share on: