CVE-2011-5000

OpenSSH < 5.8 - Authenticated Denial of Service via GSSAPI Length Field

Title source: llm
STIX 2.1

Description

The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.

References (3)

Core 3
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2011/Aug/2
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0884.html
Exploit x_refsource_misc
http://site.pi3.com.pl/adv/ssh_1.txt

Scores

EPSS 0.0022
EPSS Percentile 44.7%

Details

CWE
CWE-189
Status published
Products (50)
openbsd/openssh 1.2
openbsd/openssh 1.2.1
openbsd/openssh 1.2.2
openbsd/openssh 1.2.3
openbsd/openssh 1.2.27
openbsd/openssh 1.3
openbsd/openssh 1.5
openbsd/openssh 1.5.7
openbsd/openssh 1.5.8
openbsd/openssh 3.0
... and 40 more
Published Apr 05, 2012
Tracked Since Feb 18, 2026