[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-2069Date: (C)2004-12-31   (M)2023-12-22


sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
BID-14963
OSVDB-16567
SECUNIA-17000
SECUNIA-17135
SECUNIA-17252
http://www.securityfocus.com/archive/1/451404/100/0/threaded
http://www.securityfocus.com/archive/1/451417/100/200/threaded
http://www.securityfocus.com/archive/1/451426/100/200/threaded
SECUNIA-22875
SECUNIA-23680
ADV-2006-4502
FLSA-2006:168935
RHSA-2005:550
http://marc.info/?l=openssh-unix-dev&m=107520317020444&w=2
http://marc.info/?l=openssh-unix-dev&m=107529205602320&w=2
http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf
http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf
http://www.vmware.com/download/esx/esx-202-200610-patch.html
http://www.vmware.com/download/esx/esx-213-200610-patch.html
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
openssh-sshdc-logingracetime-dos(20930)
oval:org.mitre.oval:def:11541

CPE    2
cpe:/a:openbsd:openssh:3.6.1p2
cpe:/a:openbsd:openssh:3.7.1p2

© SecPod Technologies