Back to search
CVE-2010-5107
Published: Mar 7, 2013
Modified: May 29, 2026
PUBLISHED
Description
The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2013:1591
vendor-advisory
x_refsource_REDHAT
HPSBMU03409
vendor-advisory
x_refsource_HP
https://bugzilla.redhat.com/show_bug.cgi?id=908707
x_refsource_CONFIRM
58162
vdb-entry
x_refsource_BID
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
x_refsource_CONFIRM
[oss-security] 20130206 Re: CVE id request: openssh?
mailing-list
x_refsource_MLIST
oval:org.mitre.oval:def:19595
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:19515
vdb-entry
signature
x_refsource_OVAL
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now