sk36343 - Check Point Response to CVE-2008-5161 - OpenSSH CBC mode information disclosure vulnerability

Check Point Response to CVE-2008-5161 - OpenSSH CBC mode information disclosure vulnerability

Please read this important update from Check Point.

Security Alert:

Low

Product: Multi-Domain Security Management, Security Gateways, Security Management

Version: R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.20, R82, R82.10

OS: Gaia

Last Modified: 2025-02-09

Symptoms

Cause

This weakness could allow an attacker who is able to inject arbitrary data into an SSH session to recover up to 32 bits (4 bytes) of data by causing an error condition.

This attack method causes the SSH session to terminate and therefore cannot be used to obtain arbitrary amounts of data from a given session.

The attack requires a high degree of control over the local network (i.e., knowledge of ongoing SSH sessions, their IP addresses, ports and sequence numbers), has a very low probability of being successful (2-18), and allows the attacker to determine very limited amount of information (4 bytes). Therefore, it does not pose a significant threat to the security in SSH on SecurePlatform / Gaia OS.

Solution

Since this issue cannot be practically exploited, Check Point will not fix it.

Note: This article is not relevant to Gaia Embedded OS (on SMB / Quantum Spark appliances) that does not use OpenSSH.

Article Properties

Access Level: General

Severity: Low

Status: Approved

Date Created: 2008-11-21

Last Modified: 2025-02-09