SSH protocol 1.5 session key recovery
| ssh-session-key-recovery (6082) |
Description:
SSH (SecureShell) could allow an attacker to obtain the session key from an SSH session, due to a vulnerability in the key exchange. SSH protocol version 1.5 uses the PKCS#1_1.5 public key encryption to make the key exchange between the client and the server upon connection. An attacker could use David Bleichenbacher's ciphertext attack to obtain the session key from an SSH session and obtain information about the crypto operation.
Platforms Affected:
- Debian, Debian Linux 2.2
- SSH, SSH
Remedy:
For SSH-1 through 1.2.31:
Upgrade to SSH2, available from the SSH Secure Shell Download Page. See References.
For Debian Linux 2.2 (potato):
Upgrade to the latest version of openssh (1.2.3-9.2 or later), as listed in DSA-027-1. See References.
For AppGate:
Apply the patch for this vulnerability, available from the AppGate Support Web or request form from support@appgate.com. See References.
For Cisco IOS 12.0 and later:
Upgrade to the latest software release, as listed in Cisco Systems Field Notice, June 27, 2001. See References.
Consequences:
Obtain Information
References:
- CIAC Information Bulletin L-047, OpenSSH SSH1 Coding Error and Server Key Vulnerability at http://www.ciac.org/ciac/bulletins/l-047.shtml.
- CIAC Information Bulletin M-017, Multiple SSH Version 1 Vulnerabilities at http://www.ciac.org/ciac/bulletins/m-017.shtml.
- Cisco Systems Inc. Security Advisory, 2001 June 27 08:00 (UTC -0800), Multiple SSH Vulnerabilities at http://www.cisco.com/warp/public/707/SSH-multiple-pub.html.
- CORE SDI S.A. Security Advisory CORE-20010116, SSH protocol 1.5 session key recovery vulnerability at http://www.corest.com/pressroom/advisories_desplegado.php?idxsection=10&idx=82.
- FreeBSD Security Advisory FreeBSD-SA-01:24, ssh at http://archives.neohapsis.com/archives/freebsd/2001-02/0207.html.
- NetBSD Security Advisory 2001-003, Secure Shell vulnerabilities and key generation at http://archives.neohapsis.com/archives/netbsd/2001-q1/0094.html. (From neohapsis)
- SSH Secure Shell Download Page, Download at http://www.ssh.com/products/ssh/download.html.
- SuSE Security Announcement SuSE-SA:2001:004, ssh at http://www.suse.com/de/security/2001_045_openssh_txt.html.
- BID-2344: PKCS #1 Version 1.5 Session Key Retrieval Vulnerability
- CVE-2001-0361: Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a Bleichenbacher attack on PKCS#1 version 1.5.
- DSA-023: inn2 -- local tempfile vulnerabilities
- DSA-027: OpenSSH -- remote exploit
- DSA-086: ssh-nonfree -- remote root exploit
- OSVDB ID: 2116: PKCS 1 Version 1.5 Session Key Retrieval
- US-CERT VU#161576: Certain implementations of SSH1 may reveal internal cryptologic state
Reported:
Feb 07, 2001
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
