Oval Definition:oval:org.mitre.oval:def:12338
Revision Date:2011-04-25Version:3
Title:Security bypass vulnerability in OpenSSH version 5.6 or lower
Description:OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-4478
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):OpenSSH
Definition Synopsis
  • OpenSSH is installed
  • AND Check if OpenSSH version is less than or equal to 5.6
  • BACK