The Register®

Original URL: http://www.theregister.co.uk/2002/12/19/ssh_flaws_sighted/

SSH flaws sighted

DON'T PANIC

By John Leyden

Posted in Security, 19th December 2002 10:12 GMT

Free whitepaper – Reshaping IT

Secure shell (SSH) protocol implementations from several vendors are subject to a number of potentially serious security flaws, security clearing house CERT warned [1] earlier this week.

Read further down the notice [2]and you'll see that most major system vendors - and OpenSSH - are immune, but there's some work ahead for users of SSH implementations for Pragma Systems, F-Secure and others.

The flaws (such as they are) could allow a remote attacker to execute arbitrary code with the privileges of a particular SSH process or cause systems to crash. The vulnerabilities affect SSH clients and servers, and they occur before user authentication takes place.

The vulnerabilities, including ever-popular buffer overflow bugs, in several SSH implementations came to light after tests using a suite called SSHredder, from a firm called Rapid 7 [3].

CERT advises affected users to apply appropriate patches or upgrade, as fixes become available. More generally, it advises access to SSH servers should be limited by firewalls and packet-filtering systems. ®

Related Stories

OpenSSH trojaned! [4]
OpenSSH hits the fan [5]
Crypto boffins question SSH security [6]