Heap
19-09-08, 04:02
A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch, and before 4.6p1-1 on sid and lenny, uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4109)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4109)