![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.53766 |
Category: | Debian Local Security Checks |
Title: | Debian Security Advisory DSA 086-1 (ssh-nonfree, ssh-socks) |
Summary: | The remote host is missing an update to ssh-nonfree, ssh-socks;announced via advisory DSA 086-1. |
Description: | Summary: The remote host is missing an update to ssh-nonfree, ssh-socks announced via advisory DSA 086-1. Vulnerability Insight: We have received reports that the SSH CRC-32 compensation attack detector vulnerability is being actively exploited. This is the same integer type error previously corrected for OpenSSH in DSA-027-1. OpenSSH (the Debian ssh package) was fixed at that time, but ssh-nonfree and ssh-socks were not. Though packages in the non-free section of the archive are not officially supported by the Debian project, we are taking the unusual step of releasing updated ssh-nonfree/ssh-socks packages for those users who have not yet migrated to OpenSSH. However, we do recommend that our users migrate to the regularly supported, DFSG-free ssh package as soon as possible. ssh 1.2.3-9.3 is the OpenSSH package available in Debian 2.2r4. The fixed ssh-nonfree/ssh-socks packages are available in version 1.2.27-6.2 for use with Debian 2.2 (potato) and version 1.2.27-8 for use with the Debian unstable/testing distribution. Note that the new ssh-nonfree/ssh-socks packages remove the setuid bit from the ssh binary, disabling rhosts-rsa authentication. If you need this functionality, run chmod u+s /usr/bin/ssh1 after installing the new package. Solution: Please install the updated package(s). CVSS Score: 4.0 CVSS Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2001-0361 BugTraq ID: 2344 http://www.securityfocus.com/bid/2344 Bugtraq: 20010207 [CORE SDI ADVISORY] SSH1 session key recovery vulnerability (Google Search) http://marc.info/?l=bugtraq&m=98158450021686&w=2 Computer Incident Advisory Center Bulletin: L-047 http://www.ciac.org/ciac/bulletins/l-047.shtml Cisco Security Advisory: 20010627 Multiple SSH Vulnerabilities Debian Security Information: DSA-023 (Google Search) http://www.debian.org/security/2001/dsa-023 Debian Security Information: DSA-027 (Google Search) http://www.debian.org/security/2001/dsa-027 Debian Security Information: DSA-086 (Google Search) http://www.debian.org/security/2001/dsa-086 FreeBSD Security Advisory: FreeBSD-SA-01:24 ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc http://www.osvdb.org/2116 SuSE Security Announcement: SuSE-SA:2001:04 (Google Search) http://www.novell.com/linux/security/advisories/adv004_ssh.html XForce ISS Database: ssh-session-key-recovery(6082) https://exchange.xforce.ibmcloud.com/vulnerabilities/6082 |
Copyright | Copyright (C) 2008 E-Soft Inc. |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |