CVE Vulnerabilities

CVE-2011-5000

Published: Apr 05, 2012 | Modified: Jul 22, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V2
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd * 5.8 (including)
Openssh Openbsd 1.2 (including) 1.2 (including)
Openssh Openbsd 1.2.1 (including) 1.2.1 (including)
Openssh Openbsd 1.2.2 (including) 1.2.2 (including)
Openssh Openbsd 1.2.3 (including) 1.2.3 (including)
Openssh Openbsd 1.2.27 (including) 1.2.27 (including)
Openssh Openbsd 1.3 (including) 1.3 (including)
Openssh Openbsd 1.5 (including) 1.5 (including)
Openssh Openbsd 1.5.7 (including) 1.5.7 (including)
Openssh Openbsd 1.5.8 (including) 1.5.8 (including)
Openssh Openbsd 3.0 (including) 3.0 (including)
Openssh Openbsd 3.0.1 (including) 3.0.1 (including)
Openssh Openbsd 3.0.1p1 (including) 3.0.1p1 (including)
Openssh Openbsd 3.0.2 (including) 3.0.2 (including)
Openssh Openbsd 3.0.2p1 (including) 3.0.2p1 (including)
Openssh Openbsd 3.0p1 (including) 3.0p1 (including)
Openssh Openbsd 3.1 (including) 3.1 (including)
Openssh Openbsd 3.1p1 (including) 3.1p1 (including)
Openssh Openbsd 3.2 (including) 3.2 (including)
Openssh Openbsd 3.2.2 (including) 3.2.2 (including)
Openssh Openbsd 3.2.2p1 (including) 3.2.2p1 (including)
Openssh Openbsd 3.2.3p1 (including) 3.2.3p1 (including)
Openssh Openbsd 3.3 (including) 3.3 (including)
Openssh Openbsd 3.3p1 (including) 3.3p1 (including)
Openssh Openbsd 3.4 (including) 3.4 (including)
Openssh Openbsd 3.4p1 (including) 3.4p1 (including)
Openssh Openbsd 3.5 (including) 3.5 (including)
Openssh Openbsd 3.5p1 (including) 3.5p1 (including)
Openssh Openbsd 3.6 (including) 3.6 (including)
Openssh Openbsd 3.6.1 (including) 3.6.1 (including)
Openssh Openbsd 3.6.1p1 (including) 3.6.1p1 (including)
Openssh Openbsd 3.6.1p2 (including) 3.6.1p2 (including)
Openssh Openbsd 3.7 (including) 3.7 (including)
Openssh Openbsd 3.7.1 (including) 3.7.1 (including)
Openssh Openbsd 3.7.1p1 (including) 3.7.1p1 (including)
Openssh Openbsd 3.7.1p2 (including) 3.7.1p2 (including)
Openssh Openbsd 3.8 (including) 3.8 (including)
Openssh Openbsd 3.8.1 (including) 3.8.1 (including)
Openssh Openbsd 3.8.1p1 (including) 3.8.1p1 (including)
Openssh Openbsd 3.9 (including) 3.9 (including)
Openssh Openbsd 3.9.1 (including) 3.9.1 (including)
Openssh Openbsd 3.9.1p1 (including) 3.9.1p1 (including)
Openssh Openbsd 4.0 (including) 4.0 (including)
Openssh Openbsd 4.0p1 (including) 4.0p1 (including)
Openssh Openbsd 4.1 (including) 4.1 (including)
Openssh Openbsd 4.1p1 (including) 4.1p1 (including)
Openssh Openbsd 4.2 (including) 4.2 (including)
Openssh Openbsd 4.2p1 (including) 4.2p1 (including)
Openssh Openbsd 4.3 (including) 4.3 (including)
Openssh Openbsd 4.3p1 (including) 4.3p1 (including)
Openssh Openbsd 4.3p2 (including) 4.3p2 (including)
Openssh Openbsd 4.4 (including) 4.4 (including)
Openssh Openbsd 4.4p1 (including) 4.4p1 (including)
Openssh Openbsd 4.5 (including) 4.5 (including)
Openssh Openbsd 4.6 (including) 4.6 (including)
Openssh Openbsd 4.7 (including) 4.7 (including)
Openssh Openbsd 4.8 (including) 4.8 (including)
Openssh Openbsd 4.9 (including) 4.9 (including)
Openssh Openbsd 5.0 (including) 5.0 (including)
Openssh Openbsd 5.1 (including) 5.1 (including)
Openssh Openbsd 5.2 (including) 5.2 (including)
Openssh Openbsd 5.3 (including) 5.3 (including)
Openssh Openbsd 5.4 (including) 5.4 (including)
Openssh Openbsd 5.5 (including) 5.5 (including)
Openssh Openbsd 5.6 (including) 5.6 (including)
Openssh Openbsd 5.7 (including) 5.7 (including)
Red Hat Enterprise Linux 6 RedHat openssh-0:5.3p1-81.el6 *
Openssh Ubuntu hardy *
Openssh Ubuntu lucid *
Openssh Ubuntu maverick *
Openssh Ubuntu natty *
Openssh Ubuntu oneiric *

References