OpenSSH memory corruption issue (CVE-2014-1692) in RSA Authentication Manager - False Positive
Originally Published: 2016-03-02
Article Number
Applies To
CVE Identifier(s)
Article Summary
CVE-2014-1692
The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does not initialize certain data structures, which might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via vectors that trigger an error condition.CVSS v2 Base Score: 7.5 HIGH
Link to Advisories
Alert Impact
Not Applicable
Alert Impact Explanation
The SUSE version of SSH is not impacted.
Notes
We do not enable JPAKE support in our openSSH releases, so SUSE Linux Enterprise and openSUSE are not affected by this problem.
Disclaimer
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 126Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 90Number of Views RSA Authentication Manager 8.x Security Vulnerabilities for OpenSSL - False Positive 200Number of Views RSA Authentication Manager 8.x Security Vulnerabilities for Apache Struts 2 - False Positive 96Number of Views RSA Authentication Manager 8.2 Multiple Vulnerabilities - False Positive 60Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?