Please enable SSH-1 protocol support

Bug #1154537 reported by Peter Meiser
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libssh (Ubuntu)
Won't Fix
Wishlist
Ubuntu Security Team

Bug Description

SSH-1 protocol support must be enabled explicitly. Please find attached a debdiff to enable it.

Revision history for this message
Peter Meiser (meiser79) wrote :
Changed in libssh (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Dimitri John Ledkov (xnox) wrote :

As far as I know, ssh-1 protocol is vulnerable to arbitary injection of data into the encrypted traffic. Thus it will be highly insecure to enable that by default. This is same reason we disable weak hash algorithms and vulnerable old ssl/tls protocols in the web-browsers we ship. I think this bug will be marked as "won't fix". Subscribing ubuntu security team to make the call.

Changed in libssh (Ubuntu):
assignee: nobody → Ubuntu Security Team (ubuntu-security)
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

We're definitely not going to be turning on ssh-1. It is obsolete and contains design flaws which impact security.

Marking as Won't Fix.

Changed in libssh (Ubuntu):
status: New → Won't Fix
Revision history for this message
Peter Meiser (meiser79) wrote :

Maybe, the reason for enabling SSH-1 is not clear.

There're still some SSH servers out there which use SSH-1 only. If it's not enabled in libssh, you can't connect to these servers with Remmina.

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

It is clear, but enabled ssh-1 support in libssh will cause it to be enabled for _all_ servers/clients/apps that use libssh in the ubuntu archive. For that reason we will not do it.

If there such acient servers, either configure them to use ssh2 or any other alternative protocols.
You mention using Remmina, so I assume you are using RDP/VNC, well just let that through directly then.
Talk to your system administrators to gain you access from stable and supported operating systems.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.