Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 12.04 LTS USN-2145-1 Critical: libssh Cryptographic Attack

ubuntu
Calendar Grey March 12, 2014
Scroller Ubuntu
Responding to the libssh flaw in Ubuntu: Security Notice USN-3004-1 outlines solutions and upgrade guidance.
A security issue was fixed in libssh.

Summary

A security issue was fixed in libssh.

Software Description:

- libssh: A tiny C SSH library

Details:

Aris Adamantiadis discovered that libssh allowed the OpenSSL PRNG state to

be reused when implementing forking servers. This could allow an attacker

to possibly obtain information about the state of the PRNG and perform

cryptographic attacks.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libssh-4                        0.5.4-1ubuntu0.1

Ubuntu 12.10:
  libssh-4                        0.5.2-1ubuntu0.12.10.3

Ubuntu 12.04 LTS:
  libssh-4                        0.5.2-1ubuntu0.12.04.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2145-1

CVE-2014-0017

Severity
critical
Lowest
Low
Medium
High
Critical

March 12, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.