SSH の脆弱性: HMAC アルゴリズムと CBC 暗号化
Issue
- NCircle によると、以下の脆弱性が RHEL 5 サーバーおよび RHEL 6 サーバーで発生しました (RHEL7 にも関係します)。
SSH Insecure HMAC Algorithms Enabled
SSH CBC Mode Ciphers Enabled
Below is the update from NCircle regarding the vulnerabilities
Vulnerability Name:SSH Insecure HMAC Algorithms Enabled
Description:Insecure HMAC Algorithms are enabled
Solution:
Disable any 96-bit HMAC Algorithms.Disable any MD5-based HMAC Algorithms.
Vulnerability Name:SSH CBC Mode Ciphers Enabled
Description:CBC Mode Ciphers are enabled on the SSH Server.
Solution:Disable CBC Mode Ciphers and use CTR Mode Ciphers
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 6
-
Red Hat Enterprise Linux 5
-
OpenSSH
- Putty
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
