← All CVEs

CVE-2008-4109

medium · 5

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.

5
CVSS
28.4%
EPSS (exploit prob.)
98th
EPSS percentile
2008-09-18
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
debianlinuxunknown
openbsdopenssh<= 4.3p2
openbsdopenssh1.2
openbsdopenssh1.2.1
openbsdopenssh1.2.2
openbsdopenssh1.2.3
openbsdopenssh1.2.27
openbsdopenssh1.3
openbsdopenssh1.5
openbsdopenssh1.5.7
openbsdopenssh1.5.8
openbsdopenssh2
openbsdopenssh2.1
openbsdopenssh2.1.1
openbsdopenssh2.2
openbsdopenssh2.3
openbsdopenssh2.3.1
openbsdopenssh2.5
openbsdopenssh2.5.1
openbsdopenssh2.5.2
openbsdopenssh2.9
openbsdopenssh2.9.9
openbsdopenssh2.9.9p2
openbsdopenssh2.9p1
openbsdopenssh2.9p2
openbsdopenssh3.0
openbsdopenssh3.0.1
openbsdopenssh3.0.1p1
openbsdopenssh3.0.2
openbsdopenssh3.0.2p1
openbsdopenssh3.0p1
openbsdopenssh3.1
openbsdopenssh3.1p1
openbsdopenssh3.2
openbsdopenssh3.2.2
openbsdopenssh3.2.2p1
openbsdopenssh3.2.3p1
openbsdopenssh3.3
openbsdopenssh3.3p1
openbsdopenssh3.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-4109