CERT issues advisory over SSH vulnerabilities

Patrick Gray
17 December 2002 12:30 PM
Tags: advisory, ssh, cert, vulnerable, secure
Vulnerabilities have been found in multiple SSH implementations, according to the latest CERT security advisory.

SSH is a widely used secure shell protocol, somewhat like an encrypted and secure -telnet" program.

The vulnerabilities may allow an attacker to take control of a server running SSH.

Rapid7, a security company, developed an SSH test suite named -SSHhredder", which was able to pinpoint the security flaws in several implementations of the SSH protocol.

Vendors listed as vulnerable in the relevant CERT vulnerability notes include F-Secure, SSH Communications security, Pragma Systems and Intersoft International.

The most widely used implementation, OpenSSH, is not vulnerable.

The official response from many of the vendors listed as vulnerable has been to deny the problem seriously affects their products.

F-Secure claim that -F-Secure SSH products are not exploitable via these attacks. While F-Secure SSH versions 3.1.0 build 11 and earlier crash on these malicious packets, we did not find ways to exploit this to gain unauthorized access or to run arbitrary code."

SSH Communications Security made a similar statement.

-SSH Secure Shell products are not exploitable via these attacks."

The original advisory is available at cert.org.

Advertisement

Talkback 0 comments


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured