Multiple Vendor SSH2 Implementation Vulnerabilities
BID:6397
Info
Multiple Vendor SSH2 Implementation Vulnerabilities
| Bugtraq ID: | 6397 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2002 12:00AM |
| Updated: | Dec 16 2002 12:00AM |
| Credit: | Discovery of these vulnerabilities is credited to Rapid 7, Inc. |
| Vulnerable: |
WinSCP WinSCP 2.0 .0 Simon Tatham PuTTY 0.53 Simon Tatham PuTTY 0.49 Simon Tatham PuTTY 0.48 Pragma Systems SecureShell 2.0 NetComposite Shellguard SSH 3.4.6 InterSoft SecureNetTerm 5.4.1 FiSSH SSH Client For Windows 1.0 A |
| Not Vulnerable: |
VanDyke SecureCRT 3.4.3 Van Dyke Technologies VShell 1.2 TTSSH TTSSH 1.5.4 Simon Tatham PuTTY 0.53 b Pragma Systems SecureShell 3.0 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 LSH LSH 1.5 InterSoft SecureNetTerm 5.4.2 BitVise WinSSHD 3.5 |
Discussion
Multiple Vendor SSH2 Implementation Vulnerabilities
Several vulnerabilities have been reported for multiple products that use the SSH2 implementation for secure communications.
The vulnerabilities have been reported to affect KEXINIT (key exchange initialization) phases of SSH communications. An attacker may exploit these vulnerabilities to perform denial of service attacks against vulnerable systems and possibly to execute malicious, attacker-supplied code.
Further information about these vulnerabilities are currently unknown.
Several vulnerabilities have been reported for multiple products that use the SSH2 implementation for secure communications.
The vulnerabilities have been reported to affect KEXINIT (key exchange initialization) phases of SSH communications. An attacker may exploit these vulnerabilities to perform denial of service attacks against vulnerable systems and possibly to execute malicious, attacker-supplied code.
Further information about these vulnerabilities are currently unknown.
Exploit / POC
Multiple Vendor SSH2 Implementation Vulnerabilities
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
Solution / Fix
Multiple Vendor SSH2 Implementation Vulnerabilities
Solution:
Cray Inc. supports a OpenSSH implementation via the Cray Open Software (COS) package. COS 3.3 will reportedly address these issues and is expected to be released at the end of December 2002. Those affected by the issues may also contact Cray Inc. to obtain a fixed version of the OpenSSH implementation that will be made available in COS 3.3.
SSH Secure Shell products do not appear to be prone to any of the vulnerabilities that have been reported.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial of service attacks via exploitation of these issues.
The following vendors have provided fixes:
Simon Tatham PuTTY 0.48
Simon Tatham PuTTY 0.49
Simon Tatham PuTTY 0.53
Pragma Systems SecureShell 2.0
InterSoft SecureNetTerm 5.4.1
Solution:
Cray Inc. supports a OpenSSH implementation via the Cray Open Software (COS) package. COS 3.3 will reportedly address these issues and is expected to be released at the end of December 2002. Those affected by the issues may also contact Cray Inc. to obtain a fixed version of the OpenSSH implementation that will be made available in COS 3.3.
SSH Secure Shell products do not appear to be prone to any of the vulnerabilities that have been reported.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial of service attacks via exploitation of these issues.
The following vendors have provided fixes:
Simon Tatham PuTTY 0.48
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Simon Tatham PuTTY 0.49
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Simon Tatham PuTTY 0.53
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Pragma Systems SecureShell 2.0
-
Pragma Systems PragmaSSHD.exe
http://www.pragmasys.com/SecureShell/Update/
InterSoft SecureNetTerm 5.4.1
-
InterSoft SecureNetTerm.exe
http://www.securenetterm.com/html/beasecurenetterm.html
References
Multiple Vendor SSH2 Implementation Vulnerabilities
References:
References:
- CERT Advisory CA-2002-36 Multiple Vulnerabilities in SSH Implementations (CERT/CC)
- F-Secure Homepage (F-Secure)
- SSH Communications Homepage (SSH Communications)