Apple Affected

Updated:  November 05, 2001

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

To address this vulnerability, Apple has updated OS X to include OpenSSH 2.9p2. For further information, please visit http://www.apple.com/support/security/security_updates.html

Cisco Affected

Updated:  September 28, 2001

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Cisco has published an advisory regarding this issue; for more information, please visit http://www.cisco.com/warp/public/707/SSH-multiple-pub.html

Conectiva Affected

Updated:  December 14, 2001

Status

Affected

Vendor Statement

Conectiva Linux has released Security Announcement CLA-2001:391 regarding this vulnerability. For more information, please see http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000391

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

F-Secure Affected

Updated:  November 05, 2001

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

F-Secure has released a public statment regarding this vulnerability; for more information, please visit http://www.f-secure.com/support/ssh/ssh1_statement2.shtml

Immunix Affected

Updated:  December 14, 2001

Status

Affected

Vendor Statement

Immunix has released Security Advisory IMNX-2001-70-009-01 to address this vulnerability. For more information, please see http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-009-01

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

MandrakeSoft Affected

Updated:  December 13, 2001

Status

Affected

Vendor Statement

MandrakeSoft has released Security Advisory MDKSA-2001-033-2 to address this issue. For more information, please see http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-033-2.php3 http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-033-1.php3 http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-033.php3

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Red Hat Affected

Updated:  December 14, 2001

Status

Affected

Vendor Statement

Red Hat has released RHSA-2001:033-04 to address this issue. For more information, please see http://www.redhat.com/support/errata/RHSA-2001-033.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

SSH Communications Security Affected

Updated:  November 05, 2001

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

SSH Communications has released a public statment regarding this vulnerability; for more information, please visit http://www.ssh.com/products/ssh/timing_analysis.cfm

Trustix Affected

Updated:  December 14, 2001

Status

Affected

Vendor Statement

Trustix Secure Linux has released Security Advisory #2001-0002 to address this issue. For more information, please see http://www.trustix.net/errata/misc/2001/TSL-2001-0002-openssh.asc.txt

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.