Damien Miller (djm@) Responds to Plaintext Recovery Attack Against SSH
November 21st, 2008 . by BSD BlogDamien Miller (djm@) issued the following advisory regarding the recent attack against SSH:
OpenSSH Security Advisory: cbc.adv
Regarding the “Plaintext Recovery Attack Against SSH” reported as
CPNI-957037:The OpenSSH team has been made aware of an attack against the SSH
protocol version 2 by researchers at the University of London.
Unfortunately, due to the report lacking any detailed technical
description of the attack and CPNI’s unwillingness to share necessary
information, we are unable to properly assess its impact.
Read more…