Back to search
CVE-2008-4109
Published: Sep 17, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-649-1
vendor-advisory
openssh-signalhandler-dos(45202)
vdb-entry
31885
third-party-advisory
1020891
vdb-entry
DSA-1638
vendor-advisory
SUSE-SR:2008:020
vendor-advisory
32080
third-party-advisory
32181
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now