Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance News & Announcements
  • Search

[ GLSA 200609-17 ] OpenSSH: Denial of Service

Read this before submitting your first post to any forum
Post Reply
Advanced search
1 post • Page 1 of 1
Author
Message
GLSA
Advocate
Advocate
Posts: 2663
Joined: Wed May 12, 2004 4:41 pm

[ GLSA 200609-17 ] OpenSSH: Denial of Service

  • Quote

Post by GLSA » Wed Sep 27, 2006 6:26 pm

Gentoo Linux Security Advisory

Title: OpenSSH: Denial of Service ([glsa=200609-17]GLSA 200609-17[/glsa])
Severity: normal
Exploitable: remote
Date: September 27, 2006
Bug(s): #148228
ID: 200609-17

Synopsis

A flaw in the OpenSSH daemon allows remote unauthenticated attackers to cause a Denial of Service.

Background

OpenSSH is a free suite of applications for the SSH protocol, developed and maintained by the OpenBSD project.

Affected Packages

Package: net-misc/openssh
Vulnerable: < 4.3_p2-r5
Unaffected: >= 4.3_p2-r5
Architectures: All supported architectures


Description

Tavis Ormandy of the Google Security Team discovered a Denial of Service vulnerability in the SSH protocol version 1 CRC compensation attack detector.

Impact

A remote unauthenticated attacker may be able to trigger excessive CPU usage by sending a pathological SSH message, denying service to other legitimate users or processes.

Workaround

The system administrator may disable SSH protocol version 1 in /etc/ssh/sshd_config.

Resolution

All OpenSSH users should upgrade to the latest version:

Code: Select all

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/openssh-4.3_p2-r5"


References

CVE-2006-4924
Last edited by GLSA on Thu Sep 28, 2006 4:17 am, edited 1 time in total.
Top
Post Reply
1 post • Page 1 of 1

Return to “News & Announcements”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Authors
Gentoo is a trademark of the Gentoo Foundation, Inc. and of Förderverein Gentoo e.V.
The contents of this document, unless otherwise expressly stated, are licensed under the CC-BY-SA-4.0 license.
The Gentoo Name and Logo Usage Guidelines apply.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy