CVE Database
/

CVE-2008-5161

Back to search

CVE-2008-5161

Published: Nov 19, 2008

Modified: May 28, 2026

PUBLISHED

Description

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.

VendorProductVersions

n/a

n/a

affected
n/a

References

247186
vendor-advisory
x_refsource_SUNALERT
32319
vdb-entry
x_refsource_BID
33121
third-party-advisory
x_refsource_SECUNIA
49872
vdb-entry
x_refsource_OSVDB
33308
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1287
vendor-advisory
x_refsource_REDHAT
1021382
vdb-entry
x_refsource_SECTRACK
50036
vdb-entry
x_refsource_OSVDB
32833
third-party-advisory
x_refsource_SECUNIA
36558
third-party-advisory
x_refsource_SECUNIA
50035
vdb-entry
x_refsource_OSVDB
1021235
vdb-entry
x_refsource_SECTRACK
34857
third-party-advisory
x_refsource_SECUNIA
ADV-2008-3173
vdb-entry
x_refsource_VUPEN
32740
third-party-advisory
x_refsource_SECUNIA
ADV-2009-1135
vdb-entry
x_refsource_VUPEN
32760
third-party-advisory
x_refsource_SECUNIA
ADV-2009-3184
vdb-entry
x_refsource_VUPEN
1021236
vdb-entry
x_refsource_SECTRACK
HPSBMA02447
vendor-advisory
x_refsource_HP
APPLE-SA-2009-11-09-1
vendor-advisory
x_refsource_APPLE
SSRT090062
vendor-advisory
x_refsource_HP
ADV-2008-3409
vdb-entry
x_refsource_VUPEN
ADV-2008-3172
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:11279
vdb-entry
signature
x_refsource_OVAL
20081121 OpenSSH security advisory: cbc.adv
mailing-list
x_refsource_BUGTRAQ
VU#958563
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now