Does vulnerability CVE-2008-5161 impact the Messaging Gateway?
search cancel

Does vulnerability CVE-2008-5161 impact the Messaging Gateway?

book

Article ID: 246098

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

You want to know if the Messaging Gateway is impacted by vulnerability CVE-2008-5161.

Environment

Release : 10.7.5

Component :

Resolution

The Messaging Gateway ships with the ability to use CBC ciphers over ssh sessions by default for compatibility.  In response to this specific vulnerability in OpenSSH, Symantec has provided the "sshd-config" command to disable the use of CBC ciphers over SSH which will mitigate the issue.  It can be run on the command line interface (CLI) when logged in to an SMG appliance as "admin".

For more specific information on the sshd-config command to limit ciphers and MACs, please see the following article:

Limiting SSH ciphers and MAC algorithms in Messaging Gateway