MNBSD-2009-5: SSH CBC-mode plaintext recovery mitigated by preferring CTR ciphers

Severity: Unknown

Affected Package: openssh

Summary: SSH CBC-mode plaintext recovery mitigated by preferring CTR ciphers

Description

To mitigate the SSH CBC-mode plaintext recovery attack, the ssh and sshd configuration files were changed to prefer CTR-mode ciphers. Users on patch level p8 were advised to add a Ciphers line prioritizing aes*-ctr and arcfour ciphers to sshd_config and ssh_config. This is a configuration-only change.

Affected Versions

openssh

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2008-5161

Published: May 21, 2009
Last Modified: May 21, 2009