| ID | Date Public | Name |
|---|
| VU#19124 | 01/20/98 | SSH authentication agent follows symlinks via
a UNIX domain socket |
| VU#13877 | 06/11/98 | Weak CRC allows packet injection into SSH
sessions encrypted with block ciphers |
| VU#40327 | 06/09/2000 | OpenSSH UseLogin option allows remote
execution of commands as root |
| VU#363181 | 12/07/2000 | OpenSSH disregards client configuration and
allows server access to ssh-agent and/or X11 after session
negotiation |
| VU#850440 | 01/16/2001 | SSH1 may generate weak passphrase when
using Secure RPC |
| VU#684820 | 01/18/2001 | SSH-1 allows client authentication to be
forwarded by a malicious server to another server |
| VU#565052 | 01/18/2001 | Passwords sent via SSH encrypted with RC4
can be easily cracked |
| VU#786900 | 01/18/2001 | SSH host key authentication can be bypassed
when DNS is used to resolve localhost |
| VU#25309 | 01/18/2001 | Weak CRC allows RC4 encrypted SSH1 packets
to be modified without notice |
| VU#118892 | 01/18/2001 | Older SSH clients do not allow users to
disable X11 forwarding |
| VU#665372 | 01/18/2001 | SSH connections using RC4 and password
authentication can be replayed |
| VU#315308 | 01/18/2001 | Weak CRC allows last block of
IDEA-encrypted SSH packet to be changed without notice |
| VU#945216 | 02/08/2001 | SSH CRC32 attack detection code contains
remote integer overflow |
| VU#596827 | 03/19/2001 | Weaknesses in the SSH protocol simplify
brute-force attacks against passwords typed in an existing SSH
session |
| VU#655259 | 06/12/2001 | OpenSSH allows arbitrary file deletion via
symlink redirection of temporary file |
| VU#737451 | 07/20/2001 | SSH Secure Shell sshd2 does not adequately
authenticate logins to accounts with encrypted password fields containing
two or fewer characters |
| VU#279763 | 11/19/2001 | RhinoSoft Serv-U remote administration
client transmits password in plaintext |
| VU#157447 | 12/04/2001 | OpenSSH UseLogin directive permits
privilege escalation |
* "CERT" 並びに "CERT Coordination Center" はU.S. Patent and Trademark Officeに登録されている。
Copyright 2001 Carnegie Mellon University.