Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.2.2021.2753
Category:Huawei EulerOS Local Security Checks
Title:Huawei EulerOS: Security Advisory for libssh (EulerOS-SA-2021-2753)
Summary:The remote host is missing an update for the Huawei EulerOS 'libssh' package(s) announced via the EulerOS-SA-2021-2753 advisory.
Description:Summary:
The remote host is missing an update for the Huawei EulerOS 'libssh' package(s) announced via the EulerOS-SA-2021-2753 advisory.

Vulnerability Insight:
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating 'secret_hash' of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.(CVE-2021-3634)

Affected Software/OS:
'libssh' package(s) on Huawei EulerOS Virtualization release 2.9.1.

Solution:
Please install the updated package(s).

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-3634
https://security.netapp.com/advisory/ntap-20211004-0003/
Debian Security Information: DSA-4965 (Google Search)
https://www.debian.org/security/2021/dsa-4965
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JKYD3ZRAMDAQX3ZW6THHUF3GXN7FF6B4/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVWAAB2XMKEUMPMDALINKAA4U2QM4LNG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DRK67AJCWYYVAGF5SGAHNZXCX3PN3ZFP/
https://security.gentoo.org/glsa/202312-05
https://bugzilla.redhat.com/show_bug.cgi?id=1978810
https://www.oracle.com/security-alerts/cpujan2022.html
CopyrightCopyright (C) 2021 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.