CVE-2011-5000
OpenSSH < 5.8 - Authenticated Denial of Service via GSSAPI Length Field
Title source: llmDescription
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.
References (3)
Core 3
Core References
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2011/Aug/2
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0884.html
Exploit x_refsource_misc
http://site.pi3.com.pl/adv/ssh_1.txt
Scores
EPSS
0.0022
EPSS Percentile
44.7%
Details
CWE
CWE-189
Status
published
Products (50)
openbsd/openssh
1.2
openbsd/openssh
1.2.1
openbsd/openssh
1.2.2
openbsd/openssh
1.2.3
openbsd/openssh
1.2.27
openbsd/openssh
1.3
openbsd/openssh
1.5
openbsd/openssh
1.5.7
openbsd/openssh
1.5.8
openbsd/openssh
3.0
... and 40 more
Published
Apr 05, 2012
Tracked Since
Feb 18, 2026