Overview
There is an information integrity vulnerability in the SSH1 protocol that allows the last block of an IDEA-encrypted session to be modified without notice.
Description
Preconditions: Session is encrypted using IDEA cipher. |
Impact
Attackers can modify the last block of an SSH packet encrypted with IDEA. |
Solution
Disable the IDEA cipher with SSH1. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
The CERT/CC thanks Antti Huima, Tuomas Aura, and Janne Salmi for their analysis and Tatu Ylonen for bringing this vulnerability to our attention.
This document was written by Jeffrey P. Lanza.
Other Information
CVE IDs: | None |
Severity Metric: | 2.06 |
Date Public: | 2001-01-18 |
Date First Published: | 2001-01-18 |
Date Last Updated: | 2002-03-05 20:23 UTC |
Document Revision: | 25 |