Multiple SSH Client Protocol Change Default Warning Weakness
BID:5284
Info
Multiple SSH Client Protocol Change Default Warning Weakness
| Bugtraq ID: | 5284 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2002 12:00AM |
| Updated: | Jul 22 2002 12:00AM |
| Credit: | Credited to stealth <[email protected]>. |
| Vulnerable: |
SSH Communications Security SSH2 for Win32 3.1.2 SSH Communications Security SSH2 for Win32 3.1.1 SSH Communications Security SSH2 for Win32 3.1 SSH Communications Security SSH2 for Unix 3.1.2 SSH Communications Security SSH2 for Unix 3.1.1 SSH Communications Security SSH2 for Unix 3.1 SSH Communications Security SSH2 3.0.1 SSH Communications Security SSH2 3.0 SSH Communications Security SSH2 2.5 SSH Communications Security SSH2 2.4 SSH Communications Security SSH2 2.3 SSH Communications Security SSH2 2.2 SSH Communications Security SSH2 2.1 SSH Communications Security SSH2 2.0.12 SSH Communications Security SSH2 2.0.11 SSH Communications Security SSH2 2.0.10 SSH Communications Security SSH2 2.0.9 SSH Communications Security SSH2 2.0.8 SSH Communications Security SSH2 2.0.7 SSH Communications Security SSH2 2.0.6 SSH Communications Security SSH2 2.0.5 SSH Communications Security SSH2 2.0.4 SSH Communications Security SSH2 2.0.3 SSH Communications Security SSH2 2.0.2 SSH Communications Security SSH2 2.0.1 SSH Communications Security SSH2 2.0 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 OpenSSH OpenSSH 2.9.9 OpenSSH OpenSSH 2.9 p2 OpenSSH OpenSSH 2.9 p1 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5.1 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 OpenSSH OpenSSH 2.2 OpenSSH OpenSSH 2.1.1 OpenSSH OpenSSH 2.1 |
| Not Vulnerable: | |
Discussion
Multiple SSH Client Protocol Change Default Warning Weakness
A weakness has been reported in multiple SSH clients which may allow a man-in-the-middle attack to occur.
SSH communication with a given server normally occurs using a given protocol such as SSH2. A given client will record the server's public key. If a new key is ever reported, the client software will report to the end user that the event should be viewed with extreme suspicion.
However, if the server negotiates an SSH connection with a protocol such as SSH1 which has not previously been used with a given client, the displayed message will only report that a new key is being presented. The end user can not be expected to understand the security implications of this event.
This may allow a man-in-the-middle attack to pass undetected by the client user.
A similar attack may be possible based on the SSH2 negotiation for a MAC algorithm.
A weakness has been reported in multiple SSH clients which may allow a man-in-the-middle attack to occur.
SSH communication with a given server normally occurs using a given protocol such as SSH2. A given client will record the server's public key. If a new key is ever reported, the client software will report to the end user that the event should be viewed with extreme suspicion.
However, if the server negotiates an SSH connection with a protocol such as SSH1 which has not previously been used with a given client, the displayed message will only report that a new key is being presented. The end user can not be expected to understand the security implications of this event.
This may allow a man-in-the-middle attack to pass undetected by the client user.
A similar attack may be possible based on the SSH2 negotiation for a MAC algorithm.
Exploit / POC
Multiple SSH Client Protocol Change Default Warning Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple SSH Client Protocol Change Default Warning Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple SSH Client Protocol Change Default Warning Weakness
References:
References:
- OpenSSH Project Homepage (OpenSSH)
- SSH Communications Homepage (SSH Communications)