Personal tools
     DOCUMENTATION

Advisories:rPSA-2010-0011

From rPath Wiki

Jump to: navigation, search

rPath Security Advisory 2010-0011-1

Published: 2010-03-07

Products

  • rPath Appliance Platform Linux Service 1
  • rPath Appliance Platform Linux Service 2
  • rPath Linux 1
  • rPath Linux 2

Rating

Minor

Exposure Level Classification

Remote User Non-deterministic Information Exposure

Updated Versions

  • gnome-ssh-askpass=conary.rpath.com@rpl:1/5.3p1-0.3-1
  • openssh=conary.rpath.com@rpl:1/5.3p1-0.3-1
  • openssh=conary.rpath.com@rpl:2/5.3p1-0.1-1
  • openssh=rap-emc.rpath.com@rpath:emc-production-1/5.3p1-1-1
  • openssh=rap-emc.rpath.com@rpath:emc-production-2/5.3p1-1-1
  • openssh-client=conary.rpath.com@rpl:1/5.3p1-0.3-1
  • openssh-client=conary.rpath.com@rpl:2/5.3p1-0.1-1
  • openssh-client=rap-emc.rpath.com@rpath:emc-production-1/5.3p1-1-1
  • openssh-client=rap-emc.rpath.com@rpath:emc-production-2/5.3p1-1-1
  • openssh-server=conary.rpath.com@rpl:1/5.3p1-0.3-1
  • openssh-server=conary.rpath.com@rpl:2/5.3p1-0.1-1
  • openssh-server=rap-emc.rpath.com@rpath:emc-production-1/5.3p1-1-1
  • openssh-server=rap-emc.rpath.com@rpath:emc-production-2/5.3p1-1-1

rPath Issue Tracking System

References

Description

In previous versions of openssh, the default cipher order preferred a
block cipher algorithm in Cipher Block Chaining (CBC) mode, which is
suspectible to a plaintext recovery attack. This update changes the
cipher order to prefer the AES CTR modes, and adds countermeasures
to mitigate attacks against CBC modes.

Copyright 2010 rPath, Inc. This file is distributed under the terms of the MIT License. A copy is available at http://www.rpath.com/permanent/mit-license.html