CVE-2015-5600

The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
𝑥
≤ 6.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
1:9.2p1-2+deb12u3
fixed
bookworm (security)
1:9.2p1-2+deb12u3
fixed
bullseye
1:8.4p1-5+deb11u3
fixed
bullseye (security)
1:8.4p1-5+deb11u3
fixed
sid
1:9.9p1-3
fixed
trixie
1:9.9p1-3
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
precise
Fixed 1:5.9p1-5ubuntu1.6
released
trusty
Fixed 1:6.6p1-2ubuntu2.2
released
vivid
Fixed 1:6.7p1-5ubuntu1.2
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 6
0:5.3p1-114.el6_7
fixed
RHEL 7
0:6.6.1p1-22.el7
fixed
openssh-askpass
RHEL 6
0:5.3p1-114.el6_7
fixed
RHEL 7
0:6.6.1p1-22.el7
fixed
openssh-clients
RHEL 6
0:5.3p1-114.el6_7
fixed
RHEL 7
0:6.6.1p1-22.el7
fixed
openssh-keycat
RHEL 7
0:6.6.1p1-22.el7
fixed
openssh-ldap
RHEL 6
0:5.3p1-114.el6_7
fixed
RHEL 7
0:6.6.1p1-22.el7
fixed
openssh-server
RHEL 6
0:5.3p1-114.el6_7
fixed
RHEL 7
0:6.6.1p1-22.el7
fixed
openssh-server-sysvinit
RHEL 7
0:6.6.1p1-22.el7
fixed
pam
RHEL 6
0:0.9.3-114.el6_7
fixed
RHEL 7
0:0.9.3-9.22.el7
fixed
References