Oval Definition:oval:org.mitre.oval:tst:31809
Comment:openssh-server is earlier than 0:3.6.1p2-33.30.6
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14544
State:oval:org.mitre.oval:ste:10020
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:11541
V
sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).
2013-04-29
BACK