Actions
Security #1278
closedssh banner parsing issue
Git IDs:
8ec28dea16080c77828412d6de01018dabc7b7c3
Severity:
Disclosure Date:
Description
Reported privately.
Updated by Victor Julien about 10 years ago
- Subject changed from ssh issue to ssh banner parsing issue
- Priority changed from Normal to High
app-layer-ssh: fix banner parser Carefully crafted SSH banner could result in parser error. CVE 2014-6603 Signed-off-by: Eric Leblond <eric@regit.org>
Reported by Steffen Bauch
Updated by Victor Julien about 10 years ago
- Status changed from Assigned to Closed
- % Done changed from 0 to 100
Updated by Victor Julien about 10 years ago
A work around is to simply disable the ssh app layer module:
app-layer: protocols: tls: enabled: yes detection-ports: dp: 443 #no-reassemble: yes dcerpc: enabled: yes ftp: enabled: yes ssh: enabled: no
Alternatively, it can be set to 'detection-only'.
Updated by Victor Julien about 4 years ago
- Tracker changed from Bug to Security
- CVE set to 2014-6603
- Git IDs updated (diff)
Actions