CVE-2005-2798: Medium severity OpenBSD OpenSSH vulnerability
sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2798?
CVE-2005-2798 has been classified as a medium severity vulnerability.
How do I fix CVE-2005-2798?
To fix CVE-2005-2798, upgrade OpenSSH to version 4.2 or later where the vulnerability is patched.
What causes the vulnerability in CVE-2005-2798?
The vulnerability in CVE-2005-2798 arises from the improper handling of GSSAPI credentials when GSSAPIDelegateCredentials is enabled.
Which versions of OpenSSH are affected by CVE-2005-2798?
OpenSSH versions before 4.2, including versions such as 3.1 to 4.0p1 are affected by CVE-2005-2798.
Who is at risk due to CVE-2005-2798?
Users of OpenSSH with enabled GSSAPIDelegateCredentials are at risk of exposing their GSSAPI credentials to untrusted clients.