The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.

  NASL family
    NASL idREDHAT-RHSA-2017-2029.NASL
    description
    last seen
    plugin id
    reporter
    title
  NASL family
    NASL idF5_BIGIP_SOL31510510.NASL
    description
    last seen
    plugin id
    reporter
    title
  NASL family
    description
    last seen
    plugin id
    reporter
    title
  NASL family
    description
    last seen
    plugin id
    reporter
    title
  NASL family
    description
    last seen
    plugin id
    reporter
    title
  NASL family
    description
    last seen
    plugin id
    reporter
    title
    NASL id
    description
    last seen
    plugin id
    reporter
    title
    NASL id
    description
    last seen
    plugin id
    reporter
    title
    description
    last seen
    plugin id
    reporter
    title
    description
    last seen
    plugin id
    reporter
    title
    NASL id
    description
    last seen
    plugin id
    reporter
    title
    description
    last seen
    plugin id
    reporter
    title
    NASL id
    description
    last seen
    plugin id
    reporter
    title
    description
    last seen
    plugin id
    reporter
    title
    NASL id
    description
    last seen
    plugin id
    reporter
    title
    NASL id
    description
    last seen
    plugin id
    reporter
    title
    NASL id
    description
    last seen
    plugin id
    reporter
    title
    description
    last seen
    plugin id
    reporter
    title


data source
last seen2016-12-08
reporterKashinath T
titleOpenSSH 7.2 Denial Of Service


titlepam_ssh_agent_auth i686 and x86_64 can't be installed side by side
  • commentRed Hat Enterprise Linux must be installed
  • AND
    • commentRed Hat Enterprise Linux 7 is installed
    • OR
      • AND
        • commentpam_ssh_agent_auth is earlier than 0:0.10.3-1.11.el7
        • commentpam_ssh_agent_auth is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh-server-sysvinit is earlier than 0:7.4p1-11.el7
        • commentopenssh-server-sysvinit is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh-ldap is earlier than 0:7.4p1-11.el7
        • commentopenssh-ldap is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh-cavs is earlier than 0:7.4p1-11.el7
        • commentopenssh-cavs is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh-askpass is earlier than 0:7.4p1-11.el7
        • commentopenssh-askpass is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh-keycat is earlier than 0:7.4p1-11.el7
        • commentopenssh-keycat is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh-clients is earlier than 0:7.4p1-11.el7
        • commentopenssh-clients is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh-server is earlier than 0:7.4p1-11.el7
        • commentopenssh-server is signed with Red Hat redhatrelease2 key
      • AND
        • commentopenssh is earlier than 0:7.4p1-11.el7
        • commentopenssh is signed with Red Hat redhatrelease2 key
titleRHSA-2017:2029: openssh security, bug fix, and enhancement update (Moderate)
  • openssh-0:7.4p1-11.el7
  • openssh-askpass-0:7.4p1-11.el7
  • openssh-cavs-0:7.4p1-11.el7
  • openssh-clients-0:7.4p1-11.el7
  • openssh-debuginfo-0:7.4p1-11.el7
  • openssh-keycat-0:7.4p1-11.el7
  • openssh-ldap-0:7.4p1-11.el7
  • openssh-server-0:7.4p1-11.el7
  • openssh-server-sysvinit-0:7.4p1-11.el7
  • pam_ssh_agent_auth-0:0.10.3-1.11.el7