Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.11342
Kategorie:Gain a shell remotely
Titel:PKCS 1 Version 1.5 Session Key Retrieval
Zusammenfassung:You are running SSH protocol version 1.5.
Beschreibung:Summary:
You are running SSH protocol version 1.5.

Vulnerability Impact:
This version allows a remote attacker to decrypt and/or
alter traffic via an attack on PKCS#1 version 1.5 knows as a Bleichenbacher attack.

Affected Software/OS:
OpenSSH up to version 2.3.0, AppGate, and SSH Communications Security
ssh-1 up to version 1.2.31 have the vulnerability present, although it may not be exploitable due to configurations.

Solution:
Patch and new version are available from SSH/OpenSSH.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:N

Querverweis: BugTraq ID: 2344
Common Vulnerability Exposure (CVE) ID: CVE-2001-0361
http://www.securityfocus.com/bid/2344
Bugtraq: 20010207 [CORE SDI ADVISORY] SSH1 session key recovery vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=98158450021686&w=2
Computer Incident Advisory Center Bulletin: L-047
http://www.ciac.org/ciac/bulletins/l-047.shtml
Cisco Security Advisory: 20010627 Multiple SSH Vulnerabilities
Debian Security Information: DSA-023 (Google Search)
http://www.debian.org/security/2001/dsa-023
Debian Security Information: DSA-027 (Google Search)
http://www.debian.org/security/2001/dsa-027
Debian Security Information: DSA-086 (Google Search)
http://www.debian.org/security/2001/dsa-086
FreeBSD Security Advisory: FreeBSD-SA-01:24
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc
http://www.osvdb.org/2116
SuSE Security Announcement: SuSE-SA:2001:04 (Google Search)
http://www.novell.com/linux/security/advisories/adv004_ssh.html
XForce ISS Database: ssh-session-key-recovery(6082)
https://exchange.xforce.ibmcloud.com/vulnerabilities/6082
CopyrightCopyright (C) 2003 Xue Yong Zhi

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.