The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6449 | vdb entry |
http://www.kb.cert.org/vuls/id/25309 | third party advisory exploit us government resource |