4
CVSSv2

CVE-2001-0361

Published: 27/06/2001 Updated: 03/05/2018
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote malicious user to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh 1.2.3

ssh ssh

openbsd openssh 2.1

openbsd openssh 2.1.1

Vendor Advisories

We have received reports that the "SSH CRC-32 compensation attack detector vulnerability" is being actively exploited This is the same integer type error previously corrected for OpenSSH in DSA-027-1 OpenSSH (the Debian ssh package) was fixed at that time, but ssh-nonfree and ssh-socks were not Though packages in the non-free section of the arch ...