CVE-2008-5161

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
openbsdopenssh
4.7p1:p1
sshtectia_client
4.0
sshtectia_client
4.0.1
sshtectia_client
4.0.3
sshtectia_client
4.0.4
sshtectia_client
4.0.5
sshtectia_client
4.2
sshtectia_client
4.2.1
sshtectia_client
4.3
sshtectia_client
4.3.1
sshtectia_client
4.3.1j:j
sshtectia_client
4.3.2
sshtectia_client
4.3.2j:j
sshtectia_client
4.3.3
sshtectia_client
4.3.4
sshtectia_client
4.3.5
sshtectia_client
4.3.6
sshtectia_client
4.3.7
sshtectia_client
4.3.8k:k
sshtectia_client
4.3.9k:k
sshtectia_client
4.4
sshtectia_client
4.4.1
sshtectia_client
4.4.2
sshtectia_client
4.4.3
sshtectia_client
4.4.4
sshtectia_client
4.4.6
sshtectia_client
4.4.7
sshtectia_client
4.4.8
sshtectia_client
4.4.9
sshtectia_client
4.4.10
sshtectia_client
4.4.11
sshtectia_client
5.0.0
sshtectia_client
5.0.0f:f
sshtectia_client
5.0.1
sshtectia_client
5.0.1f:f
sshtectia_client
5.0.2
sshtectia_client
5.0.2f:f
sshtectia_client
5.0.3
sshtectia_client
5.0.3f:f
sshtectia_client
5.1.0
sshtectia_client
5.1.1
sshtectia_client
5.1.2
sshtectia_client
5.1.3
sshtectia_client
5.2.0
sshtectia_client
5.2.1
sshtectia_client
5.2.2
sshtectia_client
5.2.3
sshtectia_client
5.2.4
sshtectia_client
5.3.0
sshtectia_client
5.3.1
sshtectia_client
5.3.2
sshtectia_client
5.3.3
sshtectia_client
5.3.5
sshtectia_client
5.3.6
sshtectia_client
5.3.7
sshtectia_client
5.3.8
sshtectia_client
6.0.0
sshtectia_client
6.0.1
sshtectia_client
6.0.2
sshtectia_client
6.0.3
sshtectia_client
6.0.4
sshtectia_connector
4.0.7
sshtectia_connector
4.1.2
sshtectia_connector
4.1.3
sshtectia_connector
4.1.5
sshtectia_connector
4.2.0
sshtectia_connector
4.3.0
sshtectia_connector
4.3.4
sshtectia_connector
4.3.5
sshtectia_connector
4.4.0
sshtectia_connector
4.4.2
sshtectia_connector
4.4.4
sshtectia_connector
4.4.6
sshtectia_connector
4.4.7
sshtectia_connector
4.4.9
sshtectia_connector
4.4.10
sshtectia_connector
5.0.0
sshtectia_connector
5.0.1
sshtectia_connector
5.0.2
sshtectia_connector
5.0.3
sshtectia_connector
5.1.0
sshtectia_connector
5.1.1
sshtectia_connector
5.1.2
sshtectia_connector
5.1.3
sshtectia_connector
5.2.2
sshtectia_connector
5.3.0
sshtectia_connector
5.3.1
sshtectia_connector
5.3.2
sshtectia_connector
5.3.3
sshtectia_connector
5.3.7
sshtectia_connector
5.3.8
sshtectia_connectsecure
6.0.0
sshtectia_connectsecure
6.0.1
sshtectia_connectsecure
6.0.2
sshtectia_connectsecure
6.0.3
sshtectia_connectsecure
6.0.4
sshtectia_server
4.0
sshtectia_server
4.0.3
sshtectia_server
4.0.4
sshtectia_server
4.0.5
sshtectia_server
4.0.7
sshtectia_server
4.1.2
sshtectia_server
4.1.3
sshtectia_server
4.1.5
sshtectia_server
4.2.0
sshtectia_server
4.2.1
sshtectia_server
4.2.2
sshtectia_server
4.3
sshtectia_server
4.3.0
sshtectia_server
4.3.1
sshtectia_server
4.3.2
sshtectia_server
4.3.3
sshtectia_server
4.3.4
sshtectia_server
4.3.5
sshtectia_server
4.3.6
sshtectia_server
4.3.7
sshtectia_server
4.4
sshtectia_server
4.4.0
sshtectia_server
4.4.1
sshtectia_server
4.4.2
sshtectia_server
4.4.4
sshtectia_server
4.4.5
sshtectia_server
4.4.6
sshtectia_server
4.4.7
sshtectia_server
4.4.8
sshtectia_server
4.4.9
sshtectia_server
4.4.10
sshtectia_server
4.4.11
sshtectia_server
5.0.0
sshtectia_server
5.0.1
sshtectia_server
5.0.2
sshtectia_server
5.0.3
sshtectia_server
5.1.0
sshtectia_server
5.1.1
sshtectia_server
5.1.1
sshtectia_server
5.1.2
sshtectia_server
5.1.3
sshtectia_server
5.2.0
sshtectia_server
5.2.0
sshtectia_server
5.2.1
sshtectia_server
5.2.2
sshtectia_server
5.2.2
sshtectia_server
5.2.3
sshtectia_server
5.2.4
sshtectia_server
5.3.0
sshtectia_server
5.3.0
sshtectia_server
5.3.1
sshtectia_server
5.3.2
sshtectia_server
5.3.3
sshtectia_server
5.3.4
sshtectia_server
5.3.5
sshtectia_server
5.3.6
sshtectia_server
5.3.7
sshtectia_server
5.3.8
sshtectia_server
5.4.0
sshtectia_server
5.4.1
sshtectia_server
5.4.2
sshtectia_server
5.5.0
sshtectia_server
5.5.1
sshtectia_server
6.0.0
sshtectia_server
6.0.0
sshtectia_server
6.0.1
sshtectia_server
6.0.1
sshtectia_server
6.0.2
sshtectia_server
6.0.3
sshtectia_server
6.0.4
sshtectia_server
6.0.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bullseye (security)
1:8.4p1-5+deb11u3
fixed
bullseye
1:8.4p1-5+deb11u3
fixed
bookworm
1:9.2p1-2+deb12u3
fixed
bookworm (security)
1:9.2p1-2+deb12u3
fixed
sid
1:9.9p1-3
fixed
trixie
1:9.9p1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
gutsy
ignored
dapper
ignored
References