CVE-2005-2798Openssh vulnerability

10 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
2.7%
top 14.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 6
Latest updateMay 3

Description

sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianopenbsd/openssh< 1:4.2p1-1+3
NVDopenbsd/openssh32 versions+31

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qm2w-x4c4-rq55: sshd in OpenSSH before 42022-05-03
CVEList
CVE-2005-2798: sshd in OpenSSH before 42005-09-06
OSV
CVE-2005-2798: sshd in OpenSSH before 42005-09-06

📋Vendor Advisories

3
Ubuntu
SSH server vulnerability2005-10-18
Red Hat
security flaw2005-09-01
Debian
CVE-2005-2798: openssh - sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GS...2005

💬Community

2
Bugzilla
CVE-2005-2798 security flaw2018-08-16
Bugzilla
GSSAPI credentials can be delegated to clients who log in using non-GSSAPI methods2006-01-25
CVE-2005-2798 — Openbsd Openssh vulnerability | cvebase