[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-5161Date: (C)2008-11-19   (M)2023-12-22


Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1021235
SECTRACK-1021236
SECTRACK-1021382
http://www.securityfocus.com/archive/1/498558/100/0/threaded
http://www.securityfocus.com/archive/1/498579/100/0/threaded
SUNALERT-247186
BID-32319
SECUNIA-32740
SECUNIA-32760
SECUNIA-32833
SECUNIA-33121
SECUNIA-33308
SECUNIA-34857
SECUNIA-36558
OSVDB-49872
OSVDB-50035
OSVDB-50036
ADV-2008-3172
ADV-2008-3173
ADV-2008-3409
ADV-2009-1135
ADV-2009-3184
APPLE-SA-2009-11-09-1
HPSBMA02447
RHSA-2009:1287
VU#958563
http://isc.sans.org/diary.html?storyid=5366
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://openssh.org/txt/cbc.adv
http://support.apple.com/kb/HT3937
http://support.attachmate.com/techdocs/2398.html
http://support.avaya.com/elmodocs2/security/ASA-2008-503.htm
http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt
http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/CPNI957037.html
http://www.ssh.com/company/news/article/953/
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667
https://kc.mcafee.com/corporate/index?page=content&id=SB10106
https://kc.mcafee.com/corporate/index?page=content&id=SB10163
openssh-sshtectia-cbc-info-disclosure(46620)
oval:org.mitre.oval:def:11279

CPE    150
cpe:/a:ssh:tectia_client:5.3.7
cpe:/a:ssh:tectia_client:5.3.6
cpe:/a:ssh:tectia_client:5.3.8
cpe:/a:ssh:tectia_client:6.0.3
...
CWE    1
CWE-200
OVAL    3
oval:org.secpod.oval:def:500588
oval:org.secpod.oval:def:202081
oval:org.secpod.oval:def:202006

© SecPod Technologies