English
|
Deutsch
|
Español
|
Português
UserID:
Passwd:
new user
About:
Dedicated
|
Advanced
|
Standard
|
Recurring
|
No Risk
|
Desktop
|
Basic
|
Single
|
Security Seal
|
FAQ
Price/Feature Summary
|
Order
|
New Vulnerabilities
|
Confidentiality
|
Vulnerability Search
Vulnerability
Search
Search
61204
CVE descriptions
and
32582
test descriptions,
access
10,000+
cross references.
Tests
CVE
All
Test ID:
1.3.6.1.4.1.25623.1.0.10607
Category:
Gain root remotely
Title:
SSH1 CRC-32 compensation attack
Summary:
Checks for the remote SSH version
Description:
You are running a version of SSH which is
older than version 1.2.32,
or a version of OpenSSH which is older than
2.3.0.
This version is vulnerable to a flaw which allows
an attacker to gain a root shell on this host.
Solution :
Upgrade to version 1.2.32 of SSH which solves this problem,
or to version 2.3.0 of OpenSSH
More information:
http://www.core-sdi.com/advisories/ssh1_deattack.htm
Risk factor : High
Cross-Ref:
BugTraq ID: 2347
Common Vulnerability Exposure (CVE) ID: CVE-2001-0144
BindView Security Advisory: 20010208 Remote vulnerability in SSH daemon crc32 compensation attack detector
http://razor.bindview.com/publish/advisories/adv_ssh1crc.html
Bugtraq: 20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector (Google Search)
http://marc.theaimsgroup.com/?l=bugtraq&m=98168366406903&w=2
Bugtraq: 20011122 Secure Computing SafeWord uses vulnerable ssh server (Google Search)
http://www.cert.org/advisories/CA-2001-35.html
http://www.securityfocus.com/bid/2347
http://www.osvdb.org/503
http://www.osvdb.org/795
XForce ISS Database: ssh-deattack-overwrite-memory(6083)
http://xforce.iss.net/static/6083.php
Copyright
This script is Copyright (C) 2001 Renaud Deraison
This is only one of
32582
vulnerability tests
in our test suite. Find out more about running a
complete security audit
.
To run a free test of this vulnerability against your system, register below.
New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
Privacy
Registered User Login
UserID:
Passwd:
Forgot userid or passwd?
Email/Userid:
Home
|
About Us
|
Contact Us
|
Partner Programs
|
Privacy
|
Mailing Lists
|
Abuse
Security Audits
|
Managed DNS
|
Network Monitoring
|
Site Analyzer
|
Internet Research Reports
Web Probe
|
Whois
© 1998-2013 E-Soft Inc. All rights reserved.