Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.702879
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2879-1 (libssh - security update)
Zusammenfassung:It was discovered that libssh, a tiny C SSH library, did not reset the;state of the PRNG after accepting a connection. A server mode;application that forks itself to handle incoming connections could see;its children sharing the same PRNG state, resulting in a cryptographic;weakness and possibly the recovery of the private key.
Beschreibung:Summary:
It was discovered that libssh, a tiny C SSH library, did not reset the
state of the PRNG after accepting a connection. A server mode
application that forks itself to handle incoming connections could see
its children sharing the same PRNG state, resulting in a cryptographic
weakness and possibly the recovery of the private key.

Affected Software/OS:
libssh on Debian Linux

Solution:
For the oldstable distribution (squeeze), this problem has been fixed in
version 0.4.5-3+squeeze2.

For the stable distribution (wheezy), this problem has been fixed in
version 0.5.4-1+deb7u1.

For the testing distribution (jessie), this problem has been fixed in
version 0.5.4-3.

For the unstable distribution (sid), this problem has been fixed in
version 0.5.4-3.

We recommend that you upgrade your libssh packages.

CVSS Score:
1.9

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-0017
Debian Security Information: DSA-2879 (Google Search)
http://www.debian.org/security/2014/dsa-2879
http://www.openwall.com/lists/oss-security/2014/03/05/1
http://secunia.com/advisories/57407
SuSE Security Announcement: openSUSE-SU-2014:0366 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-03/msg00036.html
SuSE Security Announcement: openSUSE-SU-2014:0370 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-03/msg00040.html
http://www.ubuntu.com/usn/USN-2145-1
CopyrightCopyright (c) 2014 Greenbone Networks GmbH http://greenbone.net

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.