Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
BID:6405
Info
Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
| Bugtraq ID: | 6405 |
| Class: | Unknown |
| CVE: |
CVE-2002-1357 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2002 12:00AM |
| Updated: | May 16 2006 10:04PM |
| Credit: | Discovery of this vulnerability is credited to Rapid 7, Inc. |
| Vulnerable: |
WinSCP WinSCP 2.0 .0 Simon Tatham PuTTY 0.53 Simon Tatham PuTTY 0.49 Simon Tatham PuTTY 0.48 Pragma Systems SecureShell 2.0 NetComposite Shellguard SSH 3.4.6 InterSoft SecureNetTerm 5.4.1 FiSSH SSH Client For Windows 1.0 A Cisco ONS 15600 1.3 (0) Cisco ONS 15600 1.1 (1) Cisco ONS 15600 1.1 (0) Cisco ONS 15600 1.1 Cisco ONS 15600 1.0 Cisco ONS 15454SDH 4.6 (1) Cisco ONS 15454SDH 4.6 (0) Cisco ONS 15454SDH 4.5 Cisco ONS 15454SDH 4.1 (3) Cisco ONS 15454SDH 4.1 (2) Cisco ONS 15454SDH 4.1 (1) Cisco ONS 15454SDH 4.1 (0) Cisco ONS 15454SDH 4.0 (2) Cisco ONS 15454SDH 4.0 (1) Cisco ONS 15454SDH 4.0 (0) Cisco ONS 15454SDH 4.0 Cisco ONS 15454SDH 3.4 Cisco ONS 15454SDH 3.3 Cisco ONS 15454SDH 3.2 Cisco ONS 15454SDH 3.1 Cisco ONS 15454SDH 2.3 (5) Cisco ONS 15454E Optical Transport Platform 0 Cisco ONS 15454 Optical Transport Platform 4.14 Cisco ONS 15454 Optical Transport Platform 4.6 (1) Cisco ONS 15454 Optical Transport Platform 4.6 (0) Cisco ONS 15454 Optical Transport Platform 4.5 Cisco ONS 15454 Optical Transport Platform 4.1 (3) Cisco ONS 15454 Optical Transport Platform 4.1 (2) Cisco ONS 15454 Optical Transport Platform 4.1 (1) Cisco ONS 15454 Optical Transport Platform 4.1 (0) Cisco ONS 15454 Optical Transport Platform 4.1 Cisco ONS 15454 Optical Transport Platform 4.0 (2) Cisco ONS 15454 Optical Transport Platform 4.0 (1) Cisco ONS 15454 Optical Transport Platform 4.0 Cisco ONS 15454 Optical Transport Platform 3.4 Cisco ONS 15454 Optical Transport Platform 3.3 Cisco ONS 15454 Optical Transport Platform 3.2 .0 Cisco ONS 15454 Optical Transport Platform 3.1 .0 Cisco ONS 15454 Optical Transport Platform 3.0 Cisco ONS 15454 Optical Transport Platform 2.3 (5) Cisco ONS 15454 IOS-Based Blades Cisco ONS 15327 Metro Edge Optical Transport Platform Cisco ONS 15327 4.14 Cisco ONS 15327 4.6 (1) Cisco ONS 15327 4.6 (0) Cisco ONS 15327 4.1 (3) Cisco ONS 15327 4.1 (2) Cisco ONS 15327 4.1 (1) Cisco ONS 15327 4.1 (0) Cisco ONS 15327 4.0 (2) Cisco ONS 15327 4.0 (1) Cisco ONS 15327 4.0 Cisco ONS 15327 3.4 Cisco ONS 15327 3.3 Cisco ONS 15327 3.2 Cisco ONS 15327 3.1 Cisco ONS 15327 3.0 Cisco IOS 12.2T Cisco IOS 12.2S Cisco IOS 12.2 Cisco IOS 12.1T Cisco IOS 12.1EA Cisco IOS 12.1E Cisco IOS 12.0ST Cisco IOS 12.0S |
| Not Vulnerable: |
Simon Tatham PuTTY 0.53 b Pragma Systems SecureShell 3.0 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 LSH LSH 1.5 InterSoft SecureNetTerm 5.4.2 BitVise WinSSHD 3.5 |
Discussion
Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
A vulnerability with incorrect lengths of fields in SSH packets has been reported for multiple products that use SSH2 for secure communications.
The vulnerability has been reported to affect initialization, key exchange, and negotiation phases of SSH communications. An attacker may exploit the vulnerability to perform denial-of-service attacks against vulnerable systems and possibly to execute malicious, attacker-supplied code.
Further details about the vulnerability are currently unknown. This BID will be updated as more information becomes available. This vulnerability was originally described in Bugtraq ID 6397.
A vulnerability with incorrect lengths of fields in SSH packets has been reported for multiple products that use SSH2 for secure communications.
The vulnerability has been reported to affect initialization, key exchange, and negotiation phases of SSH communications. An attacker may exploit the vulnerability to perform denial-of-service attacks against vulnerable systems and possibly to execute malicious, attacker-supplied code.
Further details about the vulnerability are currently unknown. This BID will be updated as more information becomes available. This vulnerability was originally described in Bugtraq ID 6397.
Exploit / POC
Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
Exploit code (putty_ssh.pm) has been provided as part of the Metasploit Framework project.
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
Exploit code (putty_ssh.pm) has been provided as part of the Metasploit Framework project.
Solution / Fix
Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
Solution:
SSH Secure Shell products do not appear to be prone to any of the reported vulnerabilities.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial-of-service attacks via exploitation of these issues.
Please see the referenced advisories for more information.
The following vendors have provided fixes:
Cisco IOS 12.2T
Cisco IOS 12.2S
Cisco IOS 12.0ST
Cisco IOS 12.2
Cisco IOS 12.1E
Cisco IOS 12.0S
Simon Tatham PuTTY 0.48
Simon Tatham PuTTY 0.49
Simon Tatham PuTTY 0.53
Pragma Systems SecureShell 2.0
InterSoft SecureNetTerm 5.4.1
Solution:
SSH Secure Shell products do not appear to be prone to any of the reported vulnerabilities.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial-of-service attacks via exploitation of these issues.
Please see the referenced advisories for more information.
The following vendors have provided fixes:
Cisco IOS 12.2T
-
Cisco IOS 12.2(11)T3
http://www.cisco.com -
Cisco IOS 12.2(13)T1
http://www.cisco.com
Cisco IOS 12.2S
-
Cisco IOS 12.2(14)S
http://www.cisco.com
Cisco IOS 12.0ST
-
Cisco IOS 12.0(20)ST7
http://www.cisco.com -
Cisco IOS 12.0(21)ST6
http://www.cisco.com
Cisco IOS 12.2
-
Cisco IOS 12.2(12b)
http://www.cisco.com -
Cisco IOS 12.2(13a)
http://www.cisco.com
Cisco IOS 12.1E
-
Cisco IOS 12.1(13)E3
http://www.cisco.com
Cisco IOS 12.0S
-
Cisco IOS 12.0(21)S6
http://www.cisco.com -
Cisco IOS 12.0(22)S4
http://www.cisco.com -
Cisco IOS 12.0(23)S2
http://www.cisco.com
Simon Tatham PuTTY 0.48
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Simon Tatham PuTTY 0.49
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Simon Tatham PuTTY 0.53
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Pragma Systems SecureShell 2.0
-
Pragma Systems PragmaSSHD.exe
http://www.pragmasys.com/SecureShell/Update/
InterSoft SecureNetTerm 5.4.1
-
InterSoft SecureNetTerm.exe
http://www.securenetterm.com/html/beasecurenetterm.html
References
Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
References:
References:
- CERT Advisory CA-2002-36 Multiple Vulnerabilities in SSH Implementations (CERT/CC)
- Cisco Security Advisory: SSH Malformed Packet Vulnerabilities (Cisco Systems)
- F-Secure Homepage (F-Secure)
- SSH Communications Homepage (SSH Communications)
- Re: [IPS] PUTTY SSH-Client Exploit (Owen Dunn
)