OpenSSH Not Affected

Updated:  February 06, 2001

Status

Not Affected

Vendor Statement

See http://www.openssh.com/security.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

SSH Communications Security Affected

Updated:  February 06, 2001

Status

Affected

Vendor Statement

RC4 was disabled from SSH Corp.'s distribution in 1997.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

RC4 encryption was disabled in SSH a long time ago. Current versions of SSH do not suffer from this problem since they disallow the use of this algorithm.