Oracle Solaris Networking (MOSC)

MOSC Banner

Solaris 10 Sun_SSH impacted by CVE-2011-0539

edited Jan 15, 2014 1:13AM in Oracle Solaris Networking (MOSC) 2 commentsAnswered ✓
Hi,

Is the Solaris 10 OS provided version of ssh ( SSH-2.0-Sun_SSH_1.1.4 ),  impacted by CVE-2011-0539  ?

As I understand it is a port of OpenSSH,  with customizations.

From the National Vulnerabilties Database

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-0539

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

Thanks

John H

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center