QID 38866
Date Published: 2022-06-07
QID 38866: OpenSSH Denial of Service (DoS) Vulnerability
OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field.
Affected Versions:
OpenSSH before 5.9
QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.
Allows remote authenticated users to cause a denial of service.
Solution
Customers are advised to upgrade to OpenSSH 5.9 or later to remediate these vulnerabilities.
Vendor References
- Openssh -
seclists.org/fulldisclosure/2011/Aug/2
CVEs related to QID 38866
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2011-5000 |
|