CERT issues advisory over SSH vulnerabilities

By Patrick Gray
17 December 2002 12:30 PM
Tags: advisory, ssh, cert, vulnerable, secure
Vulnerabilities have been found in multiple SSH implementations, according to the latest CERT security advisory.

SSH is a widely used secure shell protocol, somewhat like an encrypted and secure -telnet" program.

The vulnerabilities may allow an attacker to take control of a server running SSH.

Rapid7, a security company, developed an SSH test suite named -SSHhredder", which was able to pinpoint the security flaws in several implementations of the SSH protocol.

Vendors listed as vulnerable in the relevant CERT vulnerability notes include F-Secure, SSH Communications security, Pragma Systems and Intersoft International.

The most widely used implementation, OpenSSH, is not vulnerable.

The official response from many of the vendors listed as vulnerable has been to deny the problem seriously affects their products.

F-Secure claim that -F-Secure SSH products are not exploitable via these attacks. While F-Secure SSH versions 3.1.0 build 11 and earlier crash on these malicious packets, we did not find ways to exploit this to gain unauthorized access or to run arbitrary code."

SSH Communications Security made a similar statement.

-SSH Secure Shell products are not exploitable via these attacks."

The original advisory is available at cert.org.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured