OpenSSH CBC Mode Information Disclosure Vulnerability
BID:32319
Info
OpenSSH CBC Mode Information Disclosure Vulnerability
| Bugtraq ID: | 32319 |
| Class: | Design Error |
| CVE: |
CVE-2008-5161 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2008 12:00AM |
| Updated: | Jul 06 2016 02:56PM |
| Credit: | Martin Albrecht, Kenny Paterson, and Gaven Watson |
| Vulnerable: |
Yamaha SRT100 0 Yamaha RTX3000 0 Yamaha RTX1500 Yamaha RTX1100 Yamaha RT58i 0 Yamaha RT107e 0 VanDyke SecureCRT 6.1.2 VanDyke SecureCRT 5.2.2 VanDyke SecureCRT 5.0.5 VanDyke SecureCRT 5.0.4 VanDyke SecureCRT 4.1.9 VanDyke SecureCRT 4.1.8 VanDyke SecureCRT 4.1.7 VanDyke SecureCRT 4.1.6 VanDyke SecureCRT 4.1.5 VanDyke SecureCRT 4.1.4 VanDyke SecureCRT 4.1.3 VanDyke SecureCRT 4.1.2 VanDyke SecureCRT 4.1.1 VanDyke SecureCRT 4.1 VanDyke SecureCRT 4.0.5 VanDyke SecureCRT 4.0.4 VanDyke SecureCRT 4.0.3 VanDyke SecureCRT 4.0.2 VanDyke SecureCRT 4.0.1 VanDyke SecureCRT 4.0 beta 3 VanDyke SecureCRT 4.0 beta 2 VanDyke SecureCRT 4.0 beta 1 VanDyke SecureCRT 3.4.8 VanDyke SecureCRT 3.4.7 VanDyke SecureCRT 3.4.6 VanDyke SecureCRT 3.4.5 VanDyke SecureCRT 3.4.4 VanDyke SecureCRT 3.4.3 VanDyke SecureCRT 3.4.2 VanDyke SecureCRT 3.4.1 VanDyke SecureCRT 3.4 VanDyke SecureCRT 3.3.4 VanDyke SecureCRT 3.3.3 VanDyke SecureCRT 3.3.2 VanDyke SecureCRT 3.3.1 VanDyke SecureCRT 3.3 VanDyke SecureCRT 3.2.2 VanDyke SecureCRT 3.2.1 VanDyke SecureCRT 3.2 VanDyke SecureCRT 3.1.2 VanDyke SecureCRT 3.1.1 VanDyke SecureCRT 3.1 VanDyke SecureCRT 3.0 VanDyke SecureCRT 2.4 Van Dyke Technologies VShell 3.5.1 Van Dyke Technologies VShell 1.2 Van Dyke Technologies VShell 1.0.2 Van Dyke Technologies VShell 1.0.1 Van Dyke Technologies VShell 1.0 Van Dyke Technologies VShell 3.0 Van Dyke Technologies VanDyke ClientPack 6.1.2 Van Dyke Technologies SecureFX 6.1.2 Van Dyke Technologies SecureFX 4.0.2 Van Dyke Technologies SecureFX 3.0.5 Van Dyke Technologies SecureFX 3.0.4 Van Dyke Technologies SecureFX 2.1.3 Van Dyke Technologies SecureFX 2.1.2 Van Dyke Technologies SecureFX 2.1.1 Van Dyke Technologies SecureFX 2.0.5 Van Dyke Technologies SecureFX 2.0.4 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_80 Sun OpenSolaris build snv_68 Sun OpenSolaris build snv_67 Sun OpenSolaris build snv_64 Sun OpenSolaris build snv_59 Sun OpenSolaris build snv_57 Sun OpenSolaris build snv_50 Sun OpenSolaris build snv_39 Sun OpenSolaris build snv_36 Sun OpenSolaris build snv_22 Sun OpenSolaris build snv_19 Sun OpenSolaris build snv_13 Sun OpenSolaris build snv_104 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_100 Sun OpenSolaris build snv_02 Sun OpenSolaris build snv_01 SSH Communications Security Tectia Server for Linux on IBM System z 6.0.4 SSH Communications Security Tectia Server for IBM z/OS 6.0.1 SSH Communications Security Tectia Server for IBM z/OS 6.0 SSH Communications Security Tectia Server for IBM z/OS 5.5.1 SSH Communications Security Tectia Server 6.0.4 SSH Communications Security Tectia Server 5.3.8 SSH Communications Security Tectia Server 5.2.4 SSH Communications Security Tectia Server 4.4.11 SSH Communications Security Tectia Server 4.4.6 SSH Communications Security Tectia Server 4.4.5 SSH Communications Security Tectia Server 4.4.3 SSH Communications Security Tectia Server 4.4.2 SSH Communications Security Tectia Server 4.4 SSH Communications Security Tectia Server 6.10 SSH Communications Security Tectia ConnectSecure 6.0.4 SSH Communications Security Tectia Connector 5.3.8 SSH Communications Security Tectia Connector 5.2.4 SSH Communications Security Tectia Connector 4.4.11 SSH Communications Security Tectia Client 6.0.4 SSH Communications Security Tectia Client 5.3.8 SSH Communications Security Tectia Client 5.2.4 SSH Communications Security Tectia Client 4.4.11 SSH Communications Security Tectia Client 4.4.6 SSH Communications Security Tectia Client 4.4.5 SSH Communications Security Tectia Client 4.4.4 SSH Communications Security Tectia Client 4.4.3 SSH Communications Security Tectia Client 4.4.2 SSH Communications Security Tectia Client 4.4.1 SSH Communications Security Tectia Client 4.4 SSH Communications Security Tectia Client 4.3.9 k SSH Communications Security Tectia Client 4.3.8 K SSH Communications Security Tectia Client 4.3.2 J SSH Communications Security Tectia Client 4.3.1 J SSH Communications Security Tectia Client 4.3.3-J SSH Communications Security Tectia Client 4.3.10-K rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 2 rPath Appliance Platform Linux Service 1 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server OpenSSH OpenSSH 4.2 OpenSSH OpenSSH 4.1 p1 OpenSSH OpenSSH 4.1 OpenSSH OpenSSH 4.0 p1 OpenSSH OpenSSH 4.0 OpenSSH OpenSSH 5.1 OpenSSH OpenSSH 5.0 OpenSSH OpenSSH 4.9 OpenSSH OpenSSH 4.8 OpenSSH OpenSSH 4.7p1 OpenSSH OpenSSH 4.7 OpenSSH OpenSSH 4.6p1 OpenSSH OpenSSH 4.6 OpenSSH OpenSSH 4.5 OpenSSH OpenSSH 4.4.p1 OpenSSH OpenSSH 4.4 OpenSSH OpenSSH 4.3p2 OpenSSH OpenSSH 4.3p1 OpenSSH OpenSSH 4.2p1 NetBSD NetBSD 4.0.1 NetBSD NetBSD 5.0 NetBSD NetBSD 4.0 IBM AIX 6.1 IBM AIX 5.3 IBM AIX 5.2 HP Insight Control for Linux (ICE-LX) 2.10 Gentoo Linux Avaya Voice Portal 5.0 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Avaya CMS Server 13.0 Avaya CMS Server 14.1 Avaya CMS Server 14.0 Avaya CMS Server 13.1 Avaya Aura Session Manager 1.1 Attachmate Reflection X 2008 0 Attachmate Reflection X 14.0.5 Attachmate Reflection X 14.0 Attachmate Reflection X 13.0 Attachmate Reflection X 10 Attachmate Reflection Suite for X 14.0.5 Attachmate Reflection Suite for X 10 Attachmate Reflection Standard Suite 2008 0 Attachmate Reflection FTP Client 14.0.5 Attachmate Reflection FTP Client 12.0 Attachmate Reflection FTP Client 10 Attachmate Reflection for UNIX and OpenVMS 2008 0 Attachmate Reflection for UNIX and OpenVMS 14.0.5 Attachmate Reflection for UNIX and OpenVMS 10 Attachmate Reflection for the Web 2008 0 Attachmate Reflection for the Web 9.6 Attachmate Reflection for the Web 6.0 Attachmate Reflection for Secure IT Windows Server 7.0 SP1 Attachmate Reflection for Secure IT Windows Server 6.0 Attachmate Reflection for Secure IT Windows Client 7.0 SP1 Attachmate Reflection for Secure IT Windows Client 6.0 Attachmate Reflection for Secure IT UNIX Server 7.0 SP1 Attachmate Reflection for Secure IT UNIX Server 6.0 Attachmate Reflection for Secure IT UNIX Client 7.0 SP1 Attachmate Reflection for Secure IT UNIX Client 6.0 Attachmate Reflection for IBM 2008 0 Attachmate Reflection for IBM 2007 0 Attachmate Reflection for IBM 14.0.5 Attachmate Reflection for IBM 14 Attachmate Reflection for IBM 10 Attachmate Reflection for HP 14.0.5 Attachmate Reflection for HP 10 Attachmate Reflection 13.0.5 Attachmate Reflection 13.0.4 Attachmate Reflection 14.0 SP1 Attachmate Reflection 14.0 Attachmate Reflection 13.0 Attachmate myEXTRA! Enterprise 7.1a Attachmate KEA! X 6.0 Attachmate INFOConnect 7.5 Attachmate F-Secure SSH Server for Windows 5.0 Attachmate F-Secure SSH Server for UNIX 5.0 Attachmate F-Secure SSH Client for UNIX 5.0 Attachmate EXTRA! X-treme 9.0 Attachmate EXTRA! X-treme 8.0 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.5 |
| Not Vulnerable: |
VanDyke SecureCRT 6.1.3 Van Dyke Technologies VShell 3.5.2 Van Dyke Technologies VanDyke ClientPack 6.1.3 Van Dyke Technologies SecureFX 6.1.3 Sun OpenSolaris build snv_105 SSH Communications Security Tectia Server for Linux on IBM System z 6.0.5 SSH Communications Security Tectia Server for IBM z/OS 6.0.2 SSH Communications Security Tectia Server for IBM z/OS 5.5.2 SSH Communications Security Tectia Server 6.0.5 SSH Communications Security Tectia Server 5.3.9 SSH Communications Security Tectia Server 5.2.5 SSH Communications Security Tectia Server 4.4.12 SSH Communications Security Tectia ConnectSecure 6.0.5 SSH Communications Security Tectia Client 6.0.5 SSH Communications Security Tectia Client 5.3.9 SSH Communications Security Tectia Client 5.2.5 SSH Communications Security Tectia Client 4.4.12 SSH Communications Security Tectia Client 4.3.4-J OpenSSH OpenSSH 5.2p1 OpenSSH OpenSSH 5.2 HP Insight Control 6.0 Attachmate Reflection X 14.1 Attachmate Reflection 14.1 Apple Mac OS X Server 10.6.2 Apple Mac OS X 10.6.2 |
Discussion
OpenSSH CBC Mode Information Disclosure Vulnerability
OpenSSH is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain four bytes of plaintext from an encrypted session.
Versions prior to OpenSSH 5.2 are vulnerable. Various versions of SSH Tectia are also affected.
OpenSSH is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain four bytes of plaintext from an encrypted session.
Versions prior to OpenSSH 5.2 are vulnerable. Various versions of SSH Tectia are also affected.
Exploit / POC
OpenSSH CBC Mode Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSSH CBC Mode Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenSSH CBC Mode Information Disclosure Vulnerability
References:
References:
- HP Insight Control suite for Linux Homepage (HP)
- InfoSec vulnerability disclosures Vulnerability in SSH (CPNI)
- OpenSSH 5.2 (OpenSSH)
- OpenSSH Homepage (OpenSSH)
- Plaintext Recovery Attack Against SSH (SSH Communications Security)
- SSH Communications Homepage (SSH Communications)
- Technical Note 1708 Security Updates and Reflection (Attachmate)
- OpenSSH security advisory: cbc.adv (Damien Miller
) - Revised: OpenSSH security advisory: cbc.adv (Damien Miller
) - AIX OpenSSH multiple vulnerabilities (IBM)
- ASA-2008-503 - A Security Vulnerability in Solaris Secure Shell (SSH) May Expose (Avaya)
- ASA-2009-406 openssh security, bug fix, and enhancement update (RHSA-2009-1287) (Avaya)
- Attachmate Security Update for CSIRTUK Vulnerability #CPNI-957: Plaintext Recove (Attachmate)
- CPNI-957037 VanDyke Security Advisory (Van Dyke)
- OpenSSH Security Advisory: cbc.adv (OpenSSH)
- RT Series Security FAQ (Yamaha)
- Solution 247186 : A Security Vulnerability in Solaris Secure Shell (SSH) May (Sun)
- Vulnerability Note VU#958563 SSH CBC vulnerability (US-CERT)