CVE-2011-5000: Low severity openssh vulnerability
The sshgssapiparseename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5000?
CVE-2011-5000 is classified as a denial of service vulnerability.
How do I fix CVE-2011-5000?
To fix CVE-2011-5000, upgrade to OpenSSH version 5.9 or later where the vulnerability is patched.
Who is affected by CVE-2011-5000?
CVE-2011-5000 affects OpenSSH versions 5.8 and earlier, particularly those using gssapi-with-mic authentication.
What kind of attack can exploit CVE-2011-5000?
CVE-2011-5000 can be exploited by remote authenticated users to cause excessive memory consumption, leading to denial of service.
Is CVE-2011-5000 a remote vulnerability?
Yes, CVE-2011-5000 can be exploited remotely, as it targets authenticated users on the system.