PT-2006-7543 · Debian · Openssh+6

CVE-2008-4109

·

Published

1970-01-01

·

Updated

2024-07-23

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openssh-client versions prior to 4.3p2-9etch3 openssh-server versions prior to 4.3p2-9etch3 openssh-server-udeb versions prior to 4.3p2-9etch3 openssh-client-udeb versions prior to 4.3p2-9etch3 ssh-krb5 versions prior to 4.3p2-9etch3 ssh-askpass-gnome versions prior to 4.3p2-9etch3 ssh versions prior to 4.3p2-9etch3 openssh-server versions prior to 4.6p1-1 openssh-client versions prior to 4.6p1-1
Description The issue affects the OpenSSH package in Debian GNU/Linux, allowing remote attackers to exploit multiple vulnerabilities and potentially disrupt the confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely, and the issue exists due to the use of functions that are not async-signal-safe in the signal handler for login timeouts, which can lead to a denial of service (connection slot exhaustion) via multiple login attempts.
Recommendations For openssh-client versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-server versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-server-udeb versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-client-udeb versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For ssh-krb5 versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For ssh-askpass-gnome versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For ssh versions prior to 4.3p2-9etch3, update to version 4.3p2-9etch3 or later. For openssh-server versions prior to 4.6p1-1, update to version 4.6p1-1 or later. For openssh-client versions prior to 4.6p1-1, update to version 4.6p1-1 or later.

Exploit

Fix

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01339
BDU:2015-01340
BDU:2015-01958
BDU:2015-01959
BDU:2015-01960
BDU:2015-01961
BDU:2015-01962
CVE-2008-4109
DSA-1638-1

Affected Products

Openssh
Openssh-Clients
Openssh-Client-Udeb
Openssh-Server
Openssh-Server-Udeb
Ssh-Askpass-Gnome
Ssh-Krb5