PT-2006-7543 · Debian · Openssh+6
CVE-2008-4109
·
Published
1970-01-01
·
Updated
2024-07-23
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
openssh-client versions prior to 4.3p2-9etch3
openssh-server versions prior to 4.3p2-9etch3
openssh-server-udeb versions prior to 4.3p2-9etch3
openssh-client-udeb versions prior to 4.3p2-9etch3
ssh-krb5 versions prior to 4.3p2-9etch3
ssh-askpass-gnome versions prior to 4.3p2-9etch3
ssh versions prior to 4.3p2-9etch3
openssh-server versions prior to 4.6p1-1
openssh-client versions prior to 4.6p1-1
Description
The issue affects the OpenSSH package in Debian GNU/Linux, allowing remote attackers to exploit multiple vulnerabilities and potentially disrupt the confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely, and the issue exists due to the use of functions that are not async-signal-safe in the signal handler for login timeouts, which can lead to a denial of service (connection slot exhaustion) via multiple login attempts.
Recommendations
For openssh-client versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later.
For openssh-server versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later.
For openssh-server-udeb versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later.
For openssh-client-udeb versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later.
For ssh-krb5 versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later.
For ssh-askpass-gnome versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later.
For ssh versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later.
For openssh-server versions prior to 4.6p1-1, update to version 4.6p1-1 or later.
For openssh-client versions prior to 4.6p1-1, update to version 4.6p1-1 or later.
Exploit
Fix
DoS
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssh
Openssh-Clients
Openssh-Client-Udeb
Openssh-Server
Openssh-Server-Udeb
Ssh-Askpass-Gnome
Ssh-Krb5