PT-2001-2674 · Openssh+3 · Ssh-Nonfree+8

Published

1970-01-01

·

Updated

2024-07-08

·

CVE-2001-0361

CVSS v2.0

4.0

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 2.3.0 ssh-1 versions prior to 1.2.31 Debian GNU/Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including ssh-socks, inn2-dev, inn2-inews, ssh-askpass-nonfree, and ssh-nonfree. These vulnerabilities can lead to a breach of confidentiality and integrity of protected information. Exploitation of these vulnerabilities can be carried out remotely. Additionally, implementations of SSH version 1.5 are vulnerable to a "Bleichenbacher attack" on PKCS#1 version 1.5, allowing a remote attacker to decrypt and/or alter traffic in certain configurations.
Recommendations For OpenSSH versions prior to 2.3.0, update to version 2.3.0 or later. For ssh-1 versions prior to 1.2.31, update to version 1.2.31 or later. For Debian GNU/Linux, apply the necessary security updates for the affected packages, including ssh-socks, inn2-dev, inn2-inews, ssh-askpass-nonfree, and ssh-nonfree. As a temporary workaround, consider restricting access to the vulnerable packages until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-02532
BDU:2015-02533
BDU:2015-02534
BDU:2015-04086
BDU:2015-04087
BDU:2015-04088
CVE-2001-0361

Affected Products

Alt Linux
Debian
Openssh
Inn2-Dev
Inn2-Inews
Ssh1
Ssh-Askpass-Nonfree
Ssh-Nonfree
Ssh-Socks