3.7 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): Low (L)
Activity log
- Created suggestion
Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
References
Affected products
Matching in nixpkgs
pkgs.openssh
Implementation of the SSH protocol
pkgs.opensshTest
Implementation of the SSH protocol
pkgs.openssh_hpn
Implementation of the SSH protocol with high performance networking patches
pkgs.openssh_gssapi
Implementation of the SSH protocol with GSSAPI support
pkgs.openssh-askpass
A passphrase dialog for OpenSSH and GTK
pkgs.opensshWithKerberos
Implementation of the SSH protocol
pkgs.openssh_hpnWithKerberos
Implementation of the SSH protocol with high performance networking patches
pkgs.perlPackages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
pkgs.perl5Packages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
pkgs.lxqt.lxqt-openssh-askpass
GUI to query passwords on behalf of SSH agents
pkgs.perl538Packages.NetOpenSSH
None
pkgs.perl540Packages.NetOpenSSH
None
Package maintainers
-
@romildo José Romildo Malaquias <malaquias@gmail.com>
-
@balsoft Alexander Bantyev <balsoft75@gmail.com>
-
@helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de>
-
@infinisil Silvan Mosberger <contact@infinisil.com>
-
@dasJ Janne Heß <janne@hess.ooo>
-
@philiptaron Philip Taron <philip.taron@gmail.com>
-
@andir Andreas Rammhold <andreas@rammhold.de>
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@wahjava Ashish SHUKLA <ashish.is@lostca.se>
-
@n3tshift n3tshift <n3tshift@tilde.pink>