Vulnerability Note VU#315308
Weak CRC allows last block of IDEA-encrypted SSH packet to be changed without notice
There is an information integrity vulnerability in the SSH1 protocol that allows the last block of an IDEA-encrypted session to be modified without notice.
Session is encrypted using IDEA cipher.
Attackers can modify the last block of an SSH packet encrypted with IDEA.
Disable the IDEA cipher with SSH1.
Systems Affected (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|SSH Communications Security||Affected||-||06 Feb 2001|
|OpenSSH||Not Affected||-||29 Oct 2001|
CVSS Metrics (Learn More)
The CERT/CC thanks Antti Huima, Tuomas Aura, and Janne Salmi for their analysis and Tatu Ylonen for bringing this vulnerability to our attention.
This document was written by Jeffrey P. Lanza.
- CVE IDs: Unknown
- Date Public: 18 Jan 2001
- Date First Published: 18 Jan 2001
- Date Last Updated: 05 Mar 2002
- Severity Metric: 2.06
- Document Revision: 25
If you have feedback, comments, or additional information about this vulnerability, please send us email.