Translated message

A translation of this page exists in English.

SSH 安全漏洞: HMAC 算法和 CBC 密码

Solution In Progress - Updated -

Issue

  • RHEL 5 和 RHEL 6 服务器上有以下安全漏洞(同样与 RHEL7 相关):
SSH Insecure HMAC Algorithms Enabled
SSH CBC Mode Ciphers Enabled

Below is the update from a security scanner regarding the vulnerabilities

Vulnerability Name: SSH Insecure HMAC Algorithms Enabled

Description: Insecure HMAC Algorithms are enabled

Solution:
Disable any 96-bit HMAC Algorithms.Disable any MD5-based HMAC Algorithms.
Vulnerability Name: SSH CBC Mode Ciphers Enabled

Description: CBC Mode Ciphers are enabled on the SSH Server.

Solution: Disable CBC Mode Ciphers and use CTR Mode Ciphers

Environment

  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 5

  • OpenSSH

  • Putty

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content