Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2001:033-2: openssh


Vulnerability Assessment Details

MDKSA-2001:033-2: openssh

Vulnerability Assessment Summary
Check for the version of the openssh package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2001:033-2 (openssh).


There are several weaknesses in various implementations of the SSH (Secure
Shell) protocols. When exploited, they let the attacker obtain sensitive
information by passively monitoring encrypted SSH sessions. The information can
later be used to speed up brute-force attacks on passwords, including the
initial login password and other passwords appearing in interactive SSH
sessions, such as those used with su. Versions of OpenSSH 2.5.2 and later have
been fixed to reduce the impact of these traffic analysis problems, and as such
all Linux- Mandrake users are encouraged to upgrade their version of openssh
immediately.
Update:
A problem was introduced with a patch applied to the OpenSSH packages released
in the previous update. This problem was due to the keepalive patch included,
and it broke interoperability with older versions of OpenSSH and SSH. This
update removes the patch, and also provides the latest version of OpenSSH which
provides a number of new features and enhancements.


Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2001:033-2
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors


NetFu Firewall 1U, Intel CPU, 8 x Gigabit, SFP, w/ pfSense, Others, NEW OPTIONS picture

NetFu Firewall 1U, Intel CPU, 8 x Gigabit, SFP, w/ pfSense, Others, NEW OPTIONS

$541.85



Cisco ASA5525-FTD-K9 Security Appliance with FirePower Services picture

Cisco ASA5525-FTD-K9 Security Appliance with FirePower Services

$1000.00



NEW NetFu Firewall Mini, Intel CPU, 6 Port Gigabit, w/ pfSense, others picture

NEW NetFu Firewall Mini, Intel CPU, 6 Port Gigabit, w/ pfSense, others

$336.00



Palo Alto PA-220 Security Appliance Firewall - NO Power adapter -  picture

Palo Alto PA-220 Security Appliance Firewall - NO Power adapter -

$33.00



Global Technology Associates GB-250 Rev B Firewall picture

Global Technology Associates GB-250 Rev B Firewall

$54.91



Palo Alto Networks PA-220 Enterprise Ethernet Network Firewall picture

Palo Alto Networks PA-220 Enterprise Ethernet Network Firewall

$55.00



Fortinet Fortigate FG-111C Firewall Appliance Fortigate-111C 64GB SSD Tested picture

Fortinet Fortigate FG-111C Firewall Appliance Fortigate-111C 64GB SSD Tested

$49.95



PFSense F80 Firewall | Atom C2358 CPU | 4 Gigabit Ports | 2GB RAM | FANLESS picture

PFSense F80 Firewall | Atom C2358 CPU | 4 Gigabit Ports | 2GB RAM | FANLESS

$75.00



Genuine Fortinet FortiGate 60E-POE Firewall Network Security ATP Bundle 2 years picture

Genuine Fortinet FortiGate 60E-POE Firewall Network Security ATP Bundle 2 years

$263.99



Cisco Meraki MX68 Cloud Managed Security Appliance Unclaimed w/ Power Adapter picture

Cisco Meraki MX68 Cloud Managed Security Appliance Unclaimed w/ Power Adapter

$157.95



Discussions

No Discussions have been posted on this vulnerability.