LWN.net Logo

openssh: denial of service

Package(s):openssh CVE #(s):CVE-2011-5000
Created:June 20, 2012 Updated:July 11, 2012
Description: From the Red Hat advisory:

A denial of service flaw was found in the OpenSSH GSSAPI authentication implementation. A remote, authenticated user could use this flaw to make the OpenSSH server daemon (sshd) use an excessive amount of memory, leading to a denial of service. GSSAPI authentication is enabled by default ("GSSAPIAuthentication yes" in "/etc/ssh/sshd_config").

Alerts:
Red Hat RHSA-2012:0884-04 2012-06-20
Oracle ELSA-2012-0884 2012-07-02
Mageia MGASA-2012-0145 2012-07-09
Scientific Linux SL-open-20120709 2012-07-09
CentOS CESA-2012:0884 2012-07-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds