CVE-2008-4109

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
openbsdopenssh
𝑥
≤ 4.3p2
openbsdopenssh
1.2
openbsdopenssh
1.2.1
openbsdopenssh
1.2.2
openbsdopenssh
1.2.3
openbsdopenssh
1.2.27
openbsdopenssh
1.3
openbsdopenssh
1.5
openbsdopenssh
1.5.7
openbsdopenssh
1.5.8
openbsdopenssh
2.1
openbsdopenssh
2.1.1
openbsdopenssh
2.2
openbsdopenssh
2.3
openbsdopenssh
2.3.1
openbsdopenssh
2.5
openbsdopenssh
2.5.1
openbsdopenssh
2.5.2
openbsdopenssh
2.9
openbsdopenssh
2.9.9
openbsdopenssh
2.9.9p2:p2
openbsdopenssh
2.9p1:p1
openbsdopenssh
2.9p2:p2
openbsdopenssh
3.0
openbsdopenssh
3.0.1
openbsdopenssh
3.0.1p1:p1
openbsdopenssh
3.0.2
openbsdopenssh
3.0.2p1:p1
openbsdopenssh
3.0p1:p1
openbsdopenssh
3.1
openbsdopenssh
3.1p1:p1
openbsdopenssh
3.2
openbsdopenssh
3.2.2
openbsdopenssh
3.2.2p1:p1
openbsdopenssh
3.2.3p1:p1
openbsdopenssh
3.3
openbsdopenssh
3.3p1:p1
openbsdopenssh
3.4
openbsdopenssh
3.4p1:p1
openbsdopenssh
3.5
openbsdopenssh
3.5p1:p1
openbsdopenssh
3.6
openbsdopenssh
3.6.1
openbsdopenssh
3.6.1p1:p1
openbsdopenssh
3.6.1p2:p2
openbsdopenssh
3.7
openbsdopenssh
3.7.1
openbsdopenssh
3.7.1p1:p1
openbsdopenssh
3.7.1p2:p2
openbsdopenssh
3.8
openbsdopenssh
3.8.1
openbsdopenssh
3.8.1p1:p1
openbsdopenssh
3.9
openbsdopenssh
3.9.1
openbsdopenssh
3.9.1p1:p1
openbsdopenssh
4.0
openbsdopenssh
4.0p1:p1
openbsdopenssh
4.1
openbsdopenssh
4.1p1:p1
openbsdopenssh
4.2
openbsdopenssh
4.2p1:p1
openbsdopenssh
4.3
openbsdopenssh
4.3p1:p1
openbsdopenssh
𝑥
≤ 4.6
openbsdopenssh
1.2
openbsdopenssh
1.2.1
openbsdopenssh
1.2.2
openbsdopenssh
1.2.3
openbsdopenssh
1.2.27
openbsdopenssh
1.3
openbsdopenssh
1.5
openbsdopenssh
1.5.7
openbsdopenssh
1.5.8
openbsdopenssh
2.1
openbsdopenssh
2.1.1
openbsdopenssh
2.2
openbsdopenssh
2.3
openbsdopenssh
2.3.1
openbsdopenssh
2.5
openbsdopenssh
2.5.1
openbsdopenssh
2.5.2
openbsdopenssh
2.9
openbsdopenssh
2.9.9
openbsdopenssh
2.9.9p2:p2
openbsdopenssh
2.9p1:p1
openbsdopenssh
2.9p2:p2
openbsdopenssh
3.0
openbsdopenssh
3.0.1
openbsdopenssh
3.0.1p1:p1
openbsdopenssh
3.0.2
openbsdopenssh
3.0.2p1:p1
openbsdopenssh
3.0p1:p1
openbsdopenssh
3.1
openbsdopenssh
3.1p1:p1
openbsdopenssh
3.2
openbsdopenssh
3.2.2
openbsdopenssh
3.2.2p1:p1
openbsdopenssh
3.2.3p1:p1
openbsdopenssh
3.3
openbsdopenssh
3.3p1:p1
openbsdopenssh
3.4
openbsdopenssh
3.4p1:p1
openbsdopenssh
3.5
openbsdopenssh
3.5p1:p1
openbsdopenssh
3.6
openbsdopenssh
3.6.1
openbsdopenssh
3.6.1p1:p1
openbsdopenssh
3.6.1p2:p2
openbsdopenssh
3.7
openbsdopenssh
3.7.1
openbsdopenssh
3.7.1p1:p1
openbsdopenssh
3.7.1p2:p2
openbsdopenssh
3.8
openbsdopenssh
3.8.1
openbsdopenssh
3.8.1p1:p1
openbsdopenssh
3.9
openbsdopenssh
3.9.1
openbsdopenssh
3.9.1p1:p1
openbsdopenssh
4.0
openbsdopenssh
4.0p1:p1
openbsdopenssh
4.1
openbsdopenssh
4.1p1:p1
openbsdopenssh
4.2
openbsdopenssh
4.2p1:p1
openbsdopenssh
4.3
openbsdopenssh
4.3p1:p1
openbsdopenssh
4.3p2:p2
openbsdopenssh
4.4
openbsdopenssh
4.4p1:p1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bullseye (security)
1:8.4p1-5+deb11u3
fixed
bullseye
1:8.4p1-5+deb11u3
fixed
bookworm
1:9.2p1-2+deb12u3
fixed
bookworm (security)
1:9.2p1-2+deb12u3
fixed
sid
1:9.9p1-3
fixed
trixie
1:9.9p1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
hardy
not-affected
gutsy
not-affected
feisty
Fixed 1:4.3p2-8ubuntu1.5
released
dapper
Fixed 1:4.2p1-7ubuntu3.5
released
Common Weakness Enumeration