OpenSSH memory corruption issue (CVE-2014-1692) in RSA Authentication Manager - False Positive
Originally Published: 2016-03-02
Article Number
Applies To
CVE Identifier(s)
Article Summary
CVE-2014-1692
The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does not initialize certain data structures, which might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via vectors that trigger an error condition.CVSS v2 Base Score: 7.5 HIGH
Link to Advisories
Alert Impact
Not Applicable
Alert Impact Explanation
The SUSE version of SSH is not impacted.
Notes
We do not enable JPAKE support in our openSSH releases, so SUSE Linux Enterprise and openSUSE are not affected by this problem.
Disclaimer
Related Articles
DSA-2019-047: RSA Authentication Manager Security Update for OpenSSH Embedded Component Vulnerabilities 33Number of Views OpenSSL Heartbeat Vulnerability (Heartbleed) in RSA products 325Number of Views Enable SSH using the command line on RSA Authentication Manager 8.4 and up 331Number of Views CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x 189Number of Views Access SSH for Identity Router Troubleshooting 177Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide
Don't see what you're looking for?