CVE Database
/

CVE-2004-2069

Back to search

CVE-2004-2069

Published: May 5, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-4502
vdb-entry
x_refsource_VUPEN
16567
vdb-entry
x_refsource_OSVDB
22875
third-party-advisory
x_refsource_SECUNIA
23680
third-party-advisory
x_refsource_SECUNIA
FLSA-2006:168935
vendor-advisory
x_refsource_FEDORA
17000
third-party-advisory
x_refsource_SECUNIA
14963
vdb-entry
x_refsource_BID
17252
third-party-advisory
x_refsource_SECUNIA
17135
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11541
vdb-entry
signature
x_refsource_OVAL
RHSA-2005:550
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now