SSH の脆弱性: HMAC アルゴリズムと CBC 暗号化
Issue
- NCircle によると、以下の脆弱性が RHEL 5 サーバーおよび RHEL 6 サーバーで発生しました (RHEL7 にも関係します)。
SSH Insecure HMAC Algorithms Enabled
SSH CBC Mode Ciphers Enabled
Below is the update from NCircle regarding the vulnerabilities
Vulnerability Name:SSH Insecure HMAC Algorithms Enabled
Description:Insecure HMAC Algorithms are enabled
Solution:
Disable any 96-bit HMAC Algorithms.Disable any MD5-based HMAC Algorithms.
Vulnerability Name:SSH CBC Mode Ciphers Enabled
Description:CBC Mode Ciphers are enabled on the SSH Server.
Solution:Disable CBC Mode Ciphers and use CTR Mode Ciphers
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 6
-
Red Hat Enterprise Linux 5
-
OpenSSH
- Putty
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.