Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2001:033-2: openssh


Vulnerability Assessment Details

MDKSA-2001:033-2: openssh

Vulnerability Assessment Summary
Check for the version of the openssh package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2001:033-2 (openssh).


There are several weaknesses in various implementations of the SSH (Secure
Shell) protocols. When exploited, they let the attacker obtain sensitive
information by passively monitoring encrypted SSH sessions. The information can
later be used to speed up brute-force attacks on passwords, including the
initial login password and other passwords appearing in interactive SSH
sessions, such as those used with su. Versions of OpenSSH 2.5.2 and later have
been fixed to reduce the impact of these traffic analysis problems, and as such
all Linux- Mandrake users are encouraged to upgrade their version of openssh
immediately.
Update:
A problem was introduced with a patch applied to the OpenSSH packages released
in the previous update. This problem was due to the keepalive patch included,
and it broke interoperability with older versions of OpenSSH and SSH. This
update removes the patch, and also provides the latest version of OpenSSH which
provides a number of new features and enhancements.


Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2001:033-2
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors

Adtran Total Access TA 924E 4243924F1 T1 VoiP Gateway Router 3rd Gen
$985.0
Adtran Total Access TA 924E 4243924F1 T1 VoiP Gateway Router 3rd Gen  pictureMulti-Tech MultiVOIP MVP810 8-Port PBX VoiP Gateway FXS FXO E&M
$399.95
Multi-Tech MultiVOIP MVP810 8-Port PBX VoiP Gateway FXS FXO E&M pictureSnom 320 Business VoIP Desk Phone
$11.9
Snom 320 Business VoIP Desk Phone pictureEricsson WebSwitch 100 G4 V2 4-Port/Line VoIP Extension Gateway Platform
$79.99
Ericsson WebSwitch 100 G4 V2 4-Port/Line VoIP Extension Gateway Platform picture


Discussions

No Discussions have been posted on this vulnerability.