Multiple Vendor SSH2 Implementation Empty Elements / Multiple Separator Vulnerabilities
BID:6408
Info
Multiple Vendor SSH2 Implementation Empty Elements / Multiple Separator Vulnerabilities
| Bugtraq ID: | 6408 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1358 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | Discovery of this vulnerability is credited to Rapid 7, Inc. |
| Vulnerable: |
WinSCP WinSCP 2.0 .0 Simon Tatham PuTTY 0.53 Simon Tatham PuTTY 0.49 Simon Tatham PuTTY 0.48 Pragma Systems SecureShell 2.0 NetComposite Shellguard SSH 3.4.6 InterSoft SecureNetTerm 5.4.1 FiSSH SSH Client For Windows 1.0 A Cisco ONS 15600 1.3 (0) Cisco ONS 15600 1.1 (1) Cisco ONS 15600 1.1 (0) Cisco ONS 15600 1.1 Cisco ONS 15600 1.0 Cisco ONS 15454SDH 4.6 (1) Cisco ONS 15454SDH 4.6 (0) Cisco ONS 15454SDH 4.5 Cisco ONS 15454SDH 4.1 (3) Cisco ONS 15454SDH 4.1 (2) Cisco ONS 15454SDH 4.1 (1) Cisco ONS 15454SDH 4.1 (0) Cisco ONS 15454SDH 4.0 (2) Cisco ONS 15454SDH 4.0 (1) Cisco ONS 15454SDH 4.0 (0) Cisco ONS 15454SDH 4.0 Cisco ONS 15454SDH 3.4 Cisco ONS 15454SDH 3.3 Cisco ONS 15454SDH 3.2 Cisco ONS 15454SDH 3.1 Cisco ONS 15454SDH 2.3 (5) Cisco ONS 15454E Optical Transport Platform 0 Cisco ONS 15454 Optical Transport Platform 4.14 Cisco ONS 15454 Optical Transport Platform 4.6 (1) Cisco ONS 15454 Optical Transport Platform 4.6 (0) Cisco ONS 15454 Optical Transport Platform 4.5 Cisco ONS 15454 Optical Transport Platform 4.1 (3) Cisco ONS 15454 Optical Transport Platform 4.1 (2) Cisco ONS 15454 Optical Transport Platform 4.1 (1) Cisco ONS 15454 Optical Transport Platform 4.1 (0) Cisco ONS 15454 Optical Transport Platform 4.1 Cisco ONS 15454 Optical Transport Platform 4.0 (2) Cisco ONS 15454 Optical Transport Platform 4.0 (1) Cisco ONS 15454 Optical Transport Platform 4.0 Cisco ONS 15454 Optical Transport Platform 3.4 Cisco ONS 15454 Optical Transport Platform 3.3 Cisco ONS 15454 Optical Transport Platform 3.2 .0 Cisco ONS 15454 Optical Transport Platform 3.1 .0 Cisco ONS 15454 Optical Transport Platform 3.0 Cisco ONS 15454 Optical Transport Platform 2.3 (5) Cisco ONS 15454 IOS-Based Blades Cisco ONS 15327 Metro Edge Optical Transport Platform Cisco ONS 15327 4.14 Cisco ONS 15327 4.6 (1) Cisco ONS 15327 4.6 (0) Cisco ONS 15327 4.1 (3) Cisco ONS 15327 4.1 (2) Cisco ONS 15327 4.1 (1) Cisco ONS 15327 4.1 (0) Cisco ONS 15327 4.0 (2) Cisco ONS 15327 4.0 (1) Cisco ONS 15327 4.0 Cisco ONS 15327 3.4 Cisco ONS 15327 3.3 Cisco ONS 15327 3.2 Cisco ONS 15327 3.1 Cisco ONS 15327 3.0 Cisco IOS 12.2T Cisco IOS 12.2S Cisco IOS 12.2 Cisco IOS 12.1T Cisco IOS 12.1EA Cisco IOS 12.1E Cisco IOS 12.0ST Cisco IOS 12.0S |
| Not Vulnerable: |
Simon Tatham PuTTY 0.53 b Pragma Systems SecureShell 3.0 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 LSH LSH 1.5 InterSoft SecureNetTerm 5.4.2 BitVise WinSSHD 3.5 |
Discussion
Multiple Vendor SSH2 Implementation Empty Elements / Multiple Separator Vulnerabilities
A vulnerability has been reported for multiple SSH2 vendors. The vulnerability is a result of SSH2 packets containing empty elements/multiple separators.
The vulnerability has been reported to affect initialization, key exchange, and negotiation phases of SSH communications. An attacker may exploit this vulnerability to perform denial of service attacks against vulnerable systems and possibly to execute malicious, attacker-supplied code.
Further details about this vulnerability are currently unknown. This BID will be updated as more information becomes available. This vulnerability was originally described in BugTraq ID 6397.
A vulnerability has been reported for multiple SSH2 vendors. The vulnerability is a result of SSH2 packets containing empty elements/multiple separators.
The vulnerability has been reported to affect initialization, key exchange, and negotiation phases of SSH communications. An attacker may exploit this vulnerability to perform denial of service attacks against vulnerable systems and possibly to execute malicious, attacker-supplied code.
Further details about this vulnerability are currently unknown. This BID will be updated as more information becomes available. This vulnerability was originally described in BugTraq ID 6397.
Exploit / POC
Multiple Vendor SSH2 Implementation Empty Elements / Multiple Separator Vulnerabilities
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The SSHredder test suite, provided by Rapid 7, is available from the following location:
http://www.rapid7.com/perl/DownloadRequest.pl?PackageChoice=666
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor SSH2 Implementation Empty Elements / Multiple Separator Vulnerabilities
Solution:
Cray Inc. supports a OpenSSH implementation via the Cray Open Software (COS) package. COS 3.3 will reportedly address these issues and is expected to be released at the end of December 2002. Those affected by the issues may also contact Cray Inc. to obtain a fixed version of the OpenSSH implementation that will be made available in COS 3.3.
SSH Secure Shell products do not appear to be prone to any of the vulnerabilities that have been reported.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial of service attacks via exploitation of these issues.
Some versions of Cisco IOS support SSH, though it is not enabled by default. Fixed versions have been made available. See the referenced advisory for more information.
Cisco has released an updated advisory. Cisco Aironet software rebuild version 12.01T1 is not vulnerable to this issue. This software will be available in the near future and will be available for download from the Software Center.
http://www.cisco.com/tacpage/sw-center/sw-wireless.shtml
Cisco has released an updated advisory to outline vulnerable Cisco ONS products and fixes. Please see the referenced advisory for more information.
The following vendors have provided fixes:
Cisco IOS 12.2T
Cisco IOS 12.0ST
Cisco IOS 12.2
Cisco IOS 12.1E
Cisco IOS 12.0S
Simon Tatham PuTTY 0.48
Simon Tatham PuTTY 0.49
Simon Tatham PuTTY 0.53
Pragma Systems SecureShell 2.0
InterSoft SecureNetTerm 5.4.1
Solution:
Cray Inc. supports a OpenSSH implementation via the Cray Open Software (COS) package. COS 3.3 will reportedly address these issues and is expected to be released at the end of December 2002. Those affected by the issues may also contact Cray Inc. to obtain a fixed version of the OpenSSH implementation that will be made available in COS 3.3.
SSH Secure Shell products do not appear to be prone to any of the vulnerabilities that have been reported.
F-Secure SSH products are not vulnerable to arbitrary code execution or denial of service attacks via exploitation of these issues.
Some versions of Cisco IOS support SSH, though it is not enabled by default. Fixed versions have been made available. See the referenced advisory for more information.
Cisco has released an updated advisory. Cisco Aironet software rebuild version 12.01T1 is not vulnerable to this issue. This software will be available in the near future and will be available for download from the Software Center.
http://www.cisco.com/tacpage/sw-center/sw-wireless.shtml
Cisco has released an updated advisory to outline vulnerable Cisco ONS products and fixes. Please see the referenced advisory for more information.
The following vendors have provided fixes:
Cisco IOS 12.2T
-
Cisco IOS 12.2(11)T3
http://www.cisco.com -
Cisco IOS 12.2(13)T1
http://www.cisco.com
Cisco IOS 12.0ST
-
Cisco IOS 12.0(20)ST7
http://www.cisco.com -
Cisco IOS 12.0(21)ST6
http://www.cisco.com
Cisco IOS 12.2
-
Cisco IOS 12.2(12b)
http://www.cisco.com -
Cisco IOS 12.2(13a)
http://www.cisco.com
Cisco IOS 12.1E
-
Cisco IOS 12.1(13)E3
http://www.cisco.com
Cisco IOS 12.0S
-
Cisco IOS 12.0(21)S6
http://www.cisco.com -
Cisco IOS 12.0(22)S4
http://www.cisco.com -
Cisco IOS 12.0(23)S2
http://www.cisco.com
Simon Tatham PuTTY 0.48
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Simon Tatham PuTTY 0.49
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Simon Tatham PuTTY 0.53
-
Simon Tatham putty0.53b
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
Pragma Systems SecureShell 2.0
-
Pragma Systems PragmaSSHD.exe
http://www.pragmasys.com/SecureShell/Update/
InterSoft SecureNetTerm 5.4.1
-
InterSoft SecureNetTerm.exe
http://www.securenetterm.com/html/beasecurenetterm.html
References
Multiple Vendor SSH2 Implementation Empty Elements / Multiple Separator Vulnerabilities
References:
References:
- CERT Advisory CA-2002-36 Multiple Vulnerabilities in SSH Implementations (CERT/CC)
- Cisco Security Advisory: SSH Malformed Packet Vulnerabilities (Cisco Systems)
- F-Secure Homepage (F-Secure)
- SSH Communications Homepage (SSH Communications)
- Re: [IPS] PUTTY SSH-Client Exploit (Owen Dunn
)