The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.
Vector
NETWORK
Complexity
MEDIUM
Authentication
SINGLE_INSTANCE
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL
Internet Initiative Japan Seil x86 Fuji Firmware 2.90
Internet Initiative Japan Seil x86 Fuji Firmware 2.51
Internet Initiative Japan Seil x86 Fuji Firmware 2.48
Internet Initiative Japan Seil x86 Fuji Firmware 2.89
Internet Initiative Japan Seil x86 Fuji Firmware 2.97
Internet Initiative Japan Seil x86 Fuji Firmware 2.87
Internet Initiative Japan Seil x86 Fuji Firmware 2.81
Internet Initiative Japan Seil x86 Fuji Firmware 2.52
Internet Initiative Japan Seil x86 Fuji Firmware 2.47
Internet Initiative Japan Seil x86 Fuji Firmware 2.85
Internet Initiative Japan Seil x86 Fuji Firmware 3.12
Internet Initiative Japan Seil x86 Fuji Firmware 2.53
Internet Initiative Japan Seil x86 Fuji Firmware 2.83
Internet Initiative Japan Seil x86 Fuji Firmware 2.49
Internet Initiative Japan Seil x86 Fuji Firmware 3.11
Internet Initiative Japan Seil x86 Fuji Firmware 3.15
Internet Initiative Japan Seil x86 Fuji Firmware 3.06
Internet Initiative Japan Seil x86 Fuji Firmware 3.13
Internet Initiative Japan Seil x86 Fuji Firmware 2.72
Internet Initiative Japan Seil x86 Fuji Firmware 3.09
Internet Initiative Japan Seil x86 Fuji Firmware 3.16
Internet Initiative Japan Seil x86 Fuji Firmware 3.14
Internet Initiative Japan Seil x86 Fuji Firmware 3.00
Internet Initiative Japan Seil x86 Fuji Firmware 3.10
Internet Initiative Japan Seil x86 Fuji Firmware 3.17
Internet Initiative Japan Seil x86 Fuji Firmware 2.73
Internet Initiative Japan Seil x86 Fuji Firmware 3.05
Internet Initiative Japan Seil x86 Fuji Firmware 2.98
Internet Initiative Japan Seil x86 Fuji Firmware 2.91
Iirf Ionic's Isapi Rewrite Filter 2.1.1.26
Internet Initiative Japan Seil x86 Fuji Firmware 3.30
Internet Initiative Japan Seil x86 Fuji Firmware 3.01
Iirf Ionic's Isapi Rewrite Filter 2.1.1.25
Internet Initiative Japan Seil x86 Fuji Firmware 2.80
Internet Initiative Japan Seil x86 Fuji Firmware 3.22
Internet Initiative Japan Seil x86 Fuji Firmware 3.19
Internet Initiative Japan SEIL x86 Fuji Firmware 3.31
Internet Initiative Japan Seil x86 Fuji Firmware 2.75
Internet Initiative Japan Seil x86 Fuji Firmware 2.93
Internet Initiative Japan Seil x86 Fuji Firmware 3.21
Internet Initiative Japan Seil x86 Fuji Firmware 2.99
Internet Initiative Japan Seil x86 Fuji Firmware 2.77
Internet Initiative Japan Seil x86 Fuji Firmware 2.92
Internet Initiative Japan Seil x86 Fuji Firmware 2.86
Internet Initiative Japan Seil x86 Fuji Firmware 2.96
Internet Initiative Japan Seil x86 Fuji Firmware 2.82
Internet Initiative Japan Seil x86 Fuji Firmware 2.88
Internet Initiative Japan Seil x86 Fuji Firmware 2.78
Internet Initiative Japan Seil x86 Fuji Firmware 2.84
Internet Initiative Japan Seil x86 Fuji Firmware 2.95
Internet Initiative Japan Seil x86 Fuji Firmware 2.79
Internet Initiative Japan Seil x86 Fuji Firmware 2.76
Internet Initiative Japan Seil x86 Fuji Firmware 2.70
Internet Initiative Japan Seil x86 Fuji Firmware 2.50
Internet Initiative Japan Seil x86 Fuji Firmware 3.20
Internet Initiative Japan Seil x86 Fuji Firmware 3.18
Internet Initiative Japan Seil x86 Fuji Firmware 2.94
Internet Initiative Japan Seil x86 Fuji Firmware 2.55
Internet Initiative Japan Seil x86 Fuji Firmware 3.07
Internet Initiative Japan Seil x86 Fuji Firmware 2.54
Internet Initiative Japan Seil x86 Fuji Firmware 2.74
Internet Initiative Japan Seil x86 Fuji Firmware 2.71
Internet Initiative Japan Seil x86 Fuji Firmware 3.04
Internet Initiative Japan Seil x86 Fuji Firmware 3.08
Internet Initiative Japan Seil x86 Fuji Firmware 3.02
Internet Initiative Japan Seil x86 Fuji Firmware 3.03
Advisory | Patch | Confirmed | Link |
---|---|---|---|
http://site.pi3.com.pl/adv/ssh_1.txt | |||
20110801 Useless OpenSSH resources exhausion bug via GSS... | |||
RHSA-2012:0884 |