PT-2006-7543 · Debian · Openssh+6

CVE-2008-4109

·

Publicado

1970-01-01

·

Atualizado

2024-07-23

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openssh-client versions prior to 4.3p2-9etch3 openssh-server versions prior to 4.3p2-9etch3 openssh-server-udeb versions prior to 4.3p2-9etch3 openssh-client-udeb versions prior to 4.3p2-9etch3 ssh-krb5 versions prior to 4.3p2-9etch3 ssh-askpass-gnome versions prior to 4.3p2-9etch3 ssh versions prior to 4.3p2-9etch3 openssh-server versions prior to 4.6p1-1 openssh-client versions prior to 4.6p1-1
Description The issue affects the OpenSSH package in Debian GNU/Linux, allowing remote attackers to exploit multiple vulnerabilities and potentially disrupt the confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely, and the issue exists due to the use of functions that are not async-signal-safe in the signal handler for login timeouts, which can lead to a denial of service (connection slot exhaustion) via multiple login attempts.
Recommendations For openssh-client versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-server versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-server-udeb versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-client-udeb versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For ssh-krb5 versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For ssh-askpass-gnome versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For ssh versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-server versions prior to 4.6p1-1, update to version 4.6p1-1 or later. For openssh-client versions prior to 4.6p1-1, update to version 4.6p1-1 or later.

Exploit

Correção

DoS

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01339
BDU:2015-01340
BDU:2015-01958
BDU:2015-01959
BDU:2015-01960
BDU:2015-01961
BDU:2015-01962
CVE-2008-4109
DSA-1638-1

Produtos afetados

Openssh
Openssh-Clients
Openssh-Client-Udeb
Openssh-Server
Openssh-Server-Udeb
Ssh-Askpass-Gnome
Ssh-Krb5