HP Tru64 SSH Undisclosed RSA Key Potential Authentication Bypass Vulnerability
BID:8492
Info
HP Tru64 SSH Undisclosed RSA Key Potential Authentication Bypass Vulnerability
| Bugtraq ID: | 8492 |
| Class: | Unknown |
| CVE: |
CVE-2003-0724 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | This vulnerability has been disclosed in a vendor advisory. |
| Vulnerable: |
Compaq Tru64 5.1 b PK2 (BL22) Compaq Tru64 5.1 a PK5 (BL23) Compaq Tru64 5.1 a PK4 (BL21) Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 a PK2 (BL2) Compaq Tru64 5.1 a PK1 (BL1) Compaq Tru64 5.1 a |
| Not Vulnerable: | |
Discussion
HP Tru64 SSH Undisclosed RSA Key Potential Authentication Bypass Vulnerability
The HP Tru64 implementation of SSH has been reported prone to an undisclosed potential authentication bypass vulnerability. The issue has been reported to present itself when RSA signatures are incorrectly processed, if SSH is implementing RSA keys and digital certificates as authentication methods.
The HP Tru64 implementation of SSH has been reported prone to an undisclosed potential authentication bypass vulnerability. The issue has been reported to present itself when RSA signatures are incorrectly processed, if SSH is implementing RSA keys and digital certificates as authentication methods.
Exploit / POC
HP Tru64 SSH Undisclosed RSA Key Potential Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP Tru64 SSH Undisclosed RSA Key Potential Authentication Bypass Vulnerability
Solution:
HP released a security advisory (SSRT3588) and fixes to address this issue in Tru64 5.1A systems. Fixes for other versions of Tru64 are pending, customers who are affected by this issue and do not have a fix available are advised to implement the workaround described in the Workaround section of this BID.
Compaq Tru64 5.1 a PK1 (BL1)
Compaq Tru64 5.1 a PK5 (BL23)
Compaq Tru64 5.1 a PK2 (BL2)
Compaq Tru64 5.1 a PK4 (BL21)
Compaq Tru64 5.1 a
Compaq Tru64 5.1 a PK3 (BL3)
Solution:
HP released a security advisory (SSRT3588) and fixes to address this issue in Tru64 5.1A systems. Fixes for other versions of Tru64 are pending, customers who are affected by this issue and do not have a fix available are advised to implement the workaround described in the Workaround section of this BID.
Compaq Tru64 5.1 a PK1 (BL1)
-
HP Tru64 UNIX Secure Shell (SSH) V3.2.1
http://h30097.www3.hp.com/unix/ssh/index.html
Compaq Tru64 5.1 a PK5 (BL23)
-
HP Tru64 UNIX Secure Shell (SSH) V3.2.1
http://h30097.www3.hp.com/unix/ssh/index.html
Compaq Tru64 5.1 a PK2 (BL2)
-
HP Tru64 UNIX Secure Shell (SSH) V3.2.1
http://h30097.www3.hp.com/unix/ssh/index.html
Compaq Tru64 5.1 a PK4 (BL21)
-
HP Tru64 UNIX Secure Shell (SSH) V3.2.1
http://h30097.www3.hp.com/unix/ssh/index.html
Compaq Tru64 5.1 a
-
HP Tru64 UNIX Secure Shell (SSH) V3.2.1
http://h30097.www3.hp.com/unix/ssh/index.html
Compaq Tru64 5.1 a PK3 (BL3)
-
HP Tru64 UNIX Secure Shell (SSH) V3.2.1
http://h30097.www3.hp.com/unix/ssh/index.html
References
HP Tru64 SSH Undisclosed RSA Key Potential Authentication Bypass Vulnerability
References:
References: