SSH Secure Shell/Tectia Server on Windows Host Identification Key Permission Vulnerability
BID:14116
Info
SSH Secure Shell/Tectia Server on Windows Host Identification Key Permission Vulnerability
| Bugtraq ID: | 14116 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2005 12:00AM |
| Updated: | Jun 30 2005 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
SSH Communications Security Tectia Server 4.3.1 SSH Communications Security Tectia Server 4.2.1 SSH Communications Security Tectia Server 4.0.5 SSH Communications Security Tectia Server 4.0.4 SSH Communications Security Tectia Server 4.0.3 SSH Communications Security Tectia Server 4.0 SSH Communications Security SSH2 for Win32 3.1.2 SSH Communications Security SSH2 for Win32 3.1.1 SSH Communications Security SSH2 for Win32 3.1 SSH Communications Security SSH2 3.2.9 SSH Communications Security SSH2 3.2.5 SSH Communications Security SSH2 3.2.4 SSH Communications Security SSH2 3.2.3 SSH Communications Security SSH2 3.2.2 SSH Communications Security SSH2 3.2.1 SSH Communications Security SSH2 3.2 SSH Communications Security SSH2 3.1.8 SSH Communications Security SSH2 3.1.7 SSH Communications Security SSH2 3.1.6 SSH Communications Security SSH2 3.1.5 SSH Communications Security SSH2 3.1.4 SSH Communications Security SSH2 3.1.3 SSH Communications Security SSH2 3.1.2 SSH Communications Security SSH2 3.1.1 SSH Communications Security SSH2 3.1 SSH Communications Security SSH2 3.0.1 SSH Communications Security SSH2 2.5 SSH Communications Security SSH2 2.4 SSH Communications Security SSH2 2.3 SSH Communications Security SSH2 2.2 SSH Communications Security SSH2 2.1 SSH Communications Security SSH2 2.0.13 SSH Communications Security SSH2 2.0.12 SSH Communications Security SSH2 2.0.11 SSH Communications Security SSH2 2.0.10 SSH Communications Security SSH2 2.0.9 SSH Communications Security SSH2 2.0.7 SSH Communications Security SSH2 2.0.6 SSH Communications Security SSH2 2.0.5 SSH Communications Security SSH2 2.0.4 SSH Communications Security SSH2 2.0.3 SSH Communications Security SSH2 2.0.2 SSH Communications Security SSH2 2.0.1 SSH Communications Security SSH2 2.0 SSH Communications Security SSH 1.2.31 SSH Communications Security SSH 1.2.31 SSH Communications Security SSH 1.2.30 SSH Communications Security SSH 1.2.29 SSH Communications Security SSH 1.2.28 SSH Communications Security SSH 1.2.27 SSH Communications Security SSH 1.2.26 SSH Communications Security SSH 1.2.25 SSH Communications Security SSH 1.2.24 SSH Communications Security SSH 1.2.23 SSH Communications Security SSH 1.2.22 SSH Communications Security SSH 1.2.21 SSH Communications Security SSH 1.2.20 SSH Communications Security SSH 1.2.19 SSH Communications Security SSH 1.2.18 SSH Communications Security SSH 1.2.17 SSH Communications Security SSH 1.2.16 SSH Communications Security SSH 1.2.15 SSH Communications Security SSH 1.2.14 SSH Communications Security SSH 1.2.13 SSH Communications Security SSH 1.2.12 SSH Communications Security SSH 1.2.11 SSH Communications Security SSH 1.2.10 SSH Communications Security SSH 1.2.9 SSH Communications Security SSH 1.2.8 SSH Communications Security SSH 1.2.7 SSH Communications Security SSH 1.2.6 SSH Communications Security SSH 1.2.5 SSH Communications Security SSH 1.2.4 SSH Communications Security SSH 1.2.3 SSH Communications Security SSH 1.2.2 SSH Communications Security SSH 1.2.1 |
| Not Vulnerable: |
SSH Communications Security Tectia Server 4.3.2 |
Discussion
SSH Secure Shell/Tectia Server on Windows Host Identification Key Permission Vulnerability
SSH Secure Shell/Tectia Server on Windows platforms are prone to a vulnerability that could disclose private keys to other users of the computer. This is due to insecure default permissions on the file containing the private key.
A malicious user who obtains the host identification key could potentially use the key in attacks against clients.
SSH Secure Shell was re-branded Tectia Server as of Tectia Server release 4.0.
SSH Secure Shell/Tectia Server on Windows platforms are prone to a vulnerability that could disclose private keys to other users of the computer. This is due to insecure default permissions on the file containing the private key.
A malicious user who obtains the host identification key could potentially use the key in attacks against clients.
SSH Secure Shell was re-branded Tectia Server as of Tectia Server release 4.0.
Exploit / POC
SSH Secure Shell/Tectia Server on Windows Host Identification Key Permission Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
SSH Secure Shell/Tectia Server on Windows Host Identification Key Permission Vulnerability
Solution:
This issue has been addressed in Tectia Server 4.3.2. Fixes are available to users with support licenses.
SSH Communications Security Tectia Server 4.0
SSH Communications Security Tectia Server 4.0.3
SSH Communications Security Tectia Server 4.0.4
SSH Communications Security Tectia Server 4.0.5
SSH Communications Security Tectia Server 4.2.1
SSH Communications Security Tectia Server 4.3.1
Solution:
This issue has been addressed in Tectia Server 4.3.2. Fixes are available to users with support licenses.
SSH Communications Security Tectia Server 4.0
-
SSH Communications Security TectiaServer-T-upgrade-4.3.2.12.zip
http://ftp.ssh.com/priv/secureshell/4.3.2-winsrv-GwvoWd/TectiaServer-T -upgrade-4.3.2.12.zip
SSH Communications Security Tectia Server 4.0.3
-
SSH Communications Security TectiaServer-T-upgrade-4.3.2.12.zip
http://ftp.ssh.com/priv/secureshell/4.3.2-winsrv-GwvoWd/TectiaServer-T -upgrade-4.3.2.12.zip
SSH Communications Security Tectia Server 4.0.4
-
SSH Communications Security TectiaServer-T-upgrade-4.3.2.12.zip
http://ftp.ssh.com/priv/secureshell/4.3.2-winsrv-GwvoWd/TectiaServer-T -upgrade-4.3.2.12.zip
SSH Communications Security Tectia Server 4.0.5
-
SSH Communications Security TectiaServer-T-upgrade-4.3.2.12.zip
http://ftp.ssh.com/priv/secureshell/4.3.2-winsrv-GwvoWd/TectiaServer-T -upgrade-4.3.2.12.zip
SSH Communications Security Tectia Server 4.2.1
-
SSH Communications Security TectiaServer-T-upgrade-4.3.2.12.zip
http://ftp.ssh.com/priv/secureshell/4.3.2-winsrv-GwvoWd/TectiaServer-T -upgrade-4.3.2.12.zip
SSH Communications Security Tectia Server 4.3.1
-
SSH Communications Security TectiaServer-T-upgrade-4.3.2.12.zip
http://ftp.ssh.com/priv/secureshell/4.3.2-winsrv-GwvoWd/TectiaServer-T -upgrade-4.3.2.12.zip
References
SSH Secure Shell/Tectia Server on Windows Host Identification Key Permission Vulnerability
References:
References:
- SSH Communications Homepage (SSH Communications)
- SSH Tectia Server Private Key Permission Vulnerability in Windows (SSH Communications Security)