← Back

CVE-2008-4109

nvd nist
Published: Sep 18, 2008Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.

Affected (68)

Products: Openbsd: Openssh
1 product
Openssh
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.3p2
Running on/withPlatform Versions
Debian
Linux
Version unknown unknown
Configuration B
67 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Openbsd
Up to 4.6
Version 1.2.1
Version 1.2.27
Version 1.2.2
Version 1.2.3
Version 1.2
Version 1.3
Version 1.5.7
Version 1.5.8
Version 1.5
Version 2.1.1
Version 2.1
Version 2.2
Version 2.3.1
Version 2.3
Version 2.5.1
Version 2.5.2
Version 2.5
Version 2.9.9
Version 2.9.9p2
Version 2.9
Version 2.9p1
Version 2.9p2
Version 2
Version 3.0.1
Version 3.0.1p1
Version 3.0.2
Version 3.0.2p1
Version 3.0
Version 3.0p1
Version 3.1
Version 3.1p1
Version 3.2.2
Version 3.2.2p1
Version 3.2.3p1
Version 3.2
Version 3.3
Version 3.3p1
Version 3.4
Version 3.4p1
Version 3.5
Version 3.5p1
Version 3.6.1
Version 3.6.1p1
Version 3.6.1p2
Version 3.6
Version 3.7.1
Version 3.7.1p1
Version 3.7.1p2
Version 3.7
Version 3.8.1
Version 3.8.1p1
Version 3.8
Version 3.9.1
Version 3.9.1p1
Version 3.9
Version 4.0
Version 4.0p1
Version 4.1
Version 4.1p1
Version 4.2
Version 4.2p1
Version 4.3
Version 4.3p1
Version 4.3p2
Version 4.4
Version 4.4p1
Running on/withPlatform Versions
Debian
Linux
Version unknown unknown

Related CWEs

References (20)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.