V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2011-5000
DEB
LowConfirmedExploit available

The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote…

CVSS
3.5
Low
EPSS
0.00
p45
Published
2011-01-01
Updated
2011-01-01
Description

The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.

Tags · CWE
CWE-189
CWE-400
CAPEC-147
CAPEC-227
CAPEC-492
Affected products
Openssh ≤ 5.8Openssh
CVSS vector
AV:N/AC:M/Au:S/C:N/I:N/A:P
Timeline
2011-01-01
Published
2011-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: S
Single
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.002 · p45
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
CVE-2008-5161
github-poc · https://github.com/talha3117/OpenSSH-4.7p1-CVE-2008-5161-Exploit
Enterprise
Affected software
ProductVendorStatus
opensshTracked
opensshTracked
opensshTracked
opensshTracked
opensshTracked
opensshTracked
opensshTracked
openssh*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities