REDHAT-BUG-2345043: Medium severity OpenSSH OpenSSH client vulnerability
Published Feb 11, 2025
·Updated
The OpenSSH client and server are vulnerable to a pre-authentication denial-of-service attack: an asymmetric resource consumption of both memory and CPU.
Affected Software
2 affected components
OpenSSH OpenSSH client
OpenSSH OpenSSH Server
Event History
Feb 11, 2025
Data Sourced
via Red Hat·07:55 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2345043?
The severity of REDHAT-BUG-2345043 is classified as medium with a risk score of 4.
2
What impact does REDHAT-BUG-2345043 have on OpenSSH?
REDHAT-BUG-2345043 allows for a pre-authentication denial-of-service attack, causing excessive memory and CPU usage.
3
How do I fix REDHAT-BUG-2345043?
To mitigate REDHAT-BUG-2345043, update to the latest version of OpenSSH that addresses this vulnerability.
4
Which versions of OpenSSH are affected by REDHAT-BUG-2345043?
REDHAT-BUG-2345043 affects both the OpenSSH client and server implementations.
5
When was REDHAT-BUG-2345043 published?
REDHAT-BUG-2345043 was published on February 11, 2025.