Title : SSH Tectia Products CBC Mode Plaintext Recovery Vulnerability VUPEN ID : VUPEN/ADV-2008-3172 CVE ID : CVE-2008-5161 CWE ID : CWE-310
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-11-18
Technical Description
A vulnerability has been identified in SSH Tectia products, which could be exploited by attackers to potentially gain knowledge of sensitive information. This issue is caused by an error when handling certain types of errors when using a block cipher algorithm in the cipher-block chaining (CBC) mode, which could allow an attacker to potentially recover up to 32 bits of plaintext from an arbitrary block of ciphertext from a SSH connection.
Credits Vulnerability reported by Martin Albrecht, Kenny Paterson and Gaven Watson (Information Security Group at Royal Holloway, University of London).
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.