SSH Communications Security Corp Information for VU#921339

SSH Tectia Client and Server ssh-signer local privilege escalation

Status

Affected

Vendor Statement

Immediate work-around is to remove the ssh-signer binary which is located in /opt/tectia/libexec/.

Note that this will disable host-based authentication of the SSH Tectia Client.
This has no adverse effect on SSH Tectia Server installation.
You can also update your system to SSH Tectia client/server solution 5.2.4 or 5.3.6, which will fix the vulnerability.
Once the update has been made, you can safely use the product again.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

If you have feedback, comments, or additional information about this vulnerability, please send us email.