OpenSSH 6.1, and prior versions, Vulnerable to Connection-slot exhaustion (CVE-2010-5107)
Issue
- OpenSSH 6.1, and prior versions, Vulnerable to Connection-slot exhaustion (CVE-2010-5107)
When establishing TCP connectivity, the enforcement of a fixed time limit prior to login completion renders OpenSSH 6.1 (and earlier versions) susceptible to a connection-slot exhaustion based Denial of Service attack.
Environment
- Red Hat Enterprise Linux (RHEL) 5
- Red Hat Enterprise Virtualization (RHEV) 3
- Red Hat Enterprise Linux (RHEL) Desktop (v. 6)
- Red Hat Enterprise Linux (RHEL) HPC Node (v. 6)
- Red Hat Enterprise Linux (RHEL) Server (v. 6)
- Red Hat Enterprise Linux (RHEL) Workstation (v. 6)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.