积极预防 及时发现
快速响应 力保恢复
当OpenSSH和其他包执行SSH协议1和2(也就是SSH-2)时存在某些弱点,允许远程攻击者通过跟...
发布时间:2001-08-22 信息来源:管理员

CNCVE编号:CNCVE-20010572 CVE编号:CAN-2001-0572 安全级别:中 漏洞中文描述: 当OpenSSH和其他包执行SSH协议1和2(也就是SSH-2)时存在某些弱点,允许远程攻击者通过跟踪来获得以下信息:(1)口令长度或长度的范围,这简化了强制口令猜测;(2)是否使用了RSA或DSA认证;(3)RSA认证中的authorized_keys数量;(4)shell命令的长度。 漏洞英文描述: The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password;(2)use RSA or DSA authentication ;(3)number of authorized_keys in RSA authentication;(4) the length of shell command. 漏洞参考: Reference: BUGTRAQ:20010318 Passive Analysis of SSH (Secure Shell) Traffic Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0225.html Reference: CONECTIVA:CLA-2001:391 Reference: URL:http://distro.conectiva.com.br/atualizacoe 系统类型:其他 漏洞类型:设计错误