A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled.
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory re
What happened
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
Does it affect you
Not enough information
No products recorded, so this cannot be matched against anything.
What to do
- Apply the vendor patch named in this advisory.
ftp.openbsd.org - Follow the vendor advisory for the fixed release and any interim mitigation.
openssh.com - Follow the vendor advisory for the fixed release and any interim mitigation.
vicarius.io
Vendor's affected list
- rhel
- Exactly 9.0
Sources
A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.