PT-2001-2674 · Openssh+3 · Ssh-Nonfree+8
Published
1970-01-01
·
Updated
2024-07-08
·
CVE-2001-0361
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions prior to 2.3.0
ssh-1 versions prior to 1.2.31
Debian GNU/Linux (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including ssh-socks, inn2-dev, inn2-inews, ssh-askpass-nonfree, and ssh-nonfree. These vulnerabilities can lead to a breach of confidentiality and integrity of protected information. Exploitation of these vulnerabilities can be carried out remotely. Additionally, implementations of SSH version 1.5 are vulnerable to a "Bleichenbacher attack" on PKCS#1 version 1.5, allowing a remote attacker to decrypt and/or alter traffic in certain configurations.
Recommendations
For OpenSSH versions prior to 2.3.0, update to version 2.3.0 or later.
For ssh-1 versions prior to 1.2.31, update to version 1.2.31 or later.
For Debian GNU/Linux, apply the necessary security updates for the affected packages, including ssh-socks, inn2-dev, inn2-inews, ssh-askpass-nonfree, and ssh-nonfree.
As a temporary workaround, consider restricting access to the vulnerable packages until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Openssh
Inn2-Dev
Inn2-Inews
Ssh1
Ssh-Askpass-Nonfree
Ssh-Nonfree
Ssh-Socks