OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
BID:54114
Info
OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
| Bugtraq ID: | 54114 |
| Class: | Design Error |
| CVE: |
CVE-2011-5000 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2012 12:00AM |
| Updated: | Nov 14 2014 12:02AM |
| Credit: | Adam Zabrocki |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 OpenSSH OpenSSH 4.2 OpenSSH OpenSSH 4.1 p1 OpenSSH OpenSSH 4.1 OpenSSH OpenSSH 4.0 p1 OpenSSH OpenSSH 4.0 OpenSSH OpenSSH 3.9 p1 OpenSSH OpenSSH 3.8.1 p1 OpenSSH OpenSSH 3.8 p1 OpenSSH OpenSSH 3.7.2 p1 OpenSSH OpenSSH 3.7.1 p2 OpenSSH OpenSSH 3.7.1 p1 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 p2 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1-7 OpenSSH OpenSSH 3.4 p1-6 OpenSSH OpenSSH 3.4 p1-5 OpenSSH OpenSSH 3.4 p1-4 OpenSSH OpenSSH 3.4 p1-3 OpenSSH OpenSSH 3.4 p1-2 OpenSSH OpenSSH 3.4 p1-1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 OpenSSH OpenSSH 2.9.9 OpenSSH OpenSSH 2.9 p2 OpenSSH OpenSSH 2.9 p1 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5.1 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 OpenSSH OpenSSH 2.2 .0p1 OpenSSH OpenSSH 2.2 OpenSSH OpenSSH 2.1.1 OpenSSH OpenSSH 2.1 OpenSSH OpenSSH 1.2.3 OpenSSH OpenSSH 1.2.2 OpenSSH OpenSSH 5.8 OpenSSH OpenSSH 5.7 OpenSSH OpenSSH 5.6p1 OpenSSH OpenSSH 5.6 OpenSSH OpenSSH 5.5 OpenSSH OpenSSH 5.4 OpenSSH OpenSSH 5.3 OpenSSH OpenSSH 5.2p1 OpenSSH OpenSSH 5.2 OpenSSH OpenSSH 5.1 OpenSSH OpenSSH 5.0p1 OpenSSH OpenSSH 5.0 OpenSSH OpenSSH 4.9 OpenSSH OpenSSH 4.8 OpenSSH OpenSSH 4.7p1 OpenSSH OpenSSH 4.7 OpenSSH OpenSSH 4.6p1 OpenSSH OpenSSH 4.6 OpenSSH OpenSSH 4.5 OpenSSH OpenSSH 4.4.p1 OpenSSH OpenSSH 4.4 OpenSSH OpenSSH 4.3p2 OpenSSH OpenSSH 4.3p1 OpenSSH OpenSSH 4.3.0 OpenSSH OpenSSH 4.2p1 Gentoo Linux Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
OpenSSH is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to trigger denial-of-service conditions due to excessive memory consumption.
OpenSSH 5.8 and prior are vulnerable.
OpenSSH is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to trigger denial-of-service conditions due to excessive memory consumption.
OpenSSH 5.8 and prior are vulnerable.
Exploit / POC
OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
References:
References:
- OpenSSH Homepage (OpenSSH)