int(4371)

Vulnerability Bulletins


Error de diseño en Sun Solaris SSH

Vulnerability classification

Property Value
Confidence level Oficial
Impact Confidencialidad
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Sun Solaris 9 SSH
Sun Solaris 10 SSH
Sun OpenSolaris SSH

Description

Se ha descubierto una vulnerabilidad en Secure Shell. La vulnerabilidad reside en un error cuando se usa SSH con el modo CBC.

Un atacante remoto podría obtener acceso a una parte de información transmitida en texto claro en una conexión SSH.

Solution



Actualización de software

Sun(247186)
De momento, no existe parche oficial para esta vulnerabilidad.
http://sunsolve.sun.com/pub-cgi/show.pl?target=patchpage

Red Hat (RHSA-2009:1287-2)
Red Hat Enterprise Linux (v. 5 servidor)
Red Hat Enterprise Linux Desktop (v. 5 cliente)
https://rhn.redhat.com/

Standar resources

Property Value
CVE CVE-2008-5161
BID 32319

Other resources

Sun Alert Notification (247186)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-247186-1

Red Hat Security Advisory (RHSA-2009:1287-2)
https://rhn.redhat.com/errata/RHSA-2009-1287.html

Version history

Version Comments Date
1.0 Aviso emitido 2008-12-16
1.1 Aviso emitido por Red Hat (RHSA-2009:1287-2) 2009-09-03