Debian OpenSSH vulnerabilities
83 known vulnerabilities affecting debian/openssh.
Total CVEs
83
CISA KEV
0
Public exploits
16
Exploited in wild
8
Severity breakdown
CRITICAL5HIGH20MEDIUM24LOW34
Vulnerabilities
Page 3 of 5
CVE-2021-28041P3HIGHCVSS 7.1fixed in openssh 1:8.4p1-5 (bookworm)2021
CVE-2021-28041 [HIGH] CVE-2021-28041: openssh - ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few ...
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Scope: local
bookworm: resolved (fixed in 1:8.4p1-5)
bullseye: resolved (fixed in 1:8.4p1-5)
forky: resolved (fixed in 1:8.4p1-5)
s
debian
CVE-2015-8325P3HIGHCVSS 7.8fixed in openssh 1:7.2p2-3 (bookworm)2015
CVE-2015-8325 [HIGH] CVE-2015-8325: openssh - The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when th...
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
Scope: local
bookworm: r
debian
CVE-2006-5794P3LOWCVSS 7.5fixed in openssh 1:4.3p2-6 (bookworm)2006
CVE-2006-5794 [HIGH] CVE-2006-5794: openssh - Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH be...
Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exis
debian
CVE-2021-41617P3HIGHCVSS 7.0fixed in openssh 1:8.7p1-1 (bookworm)2021
CVE-2021-41617 [HIGH] CVE-2021-41617: openssh - sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurati...
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies r
debian
CVE-2014-2653P3LOWCVSS 5.8fixed in openssh 1:6.6p1-1 (bookworm)2014
CVE-2014-2653 [MEDIUM] CVE-2014-2653: openssh - The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and ea...
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.
Scope: local
bookworm: resolved (fixed in 1:6.6p1-1)
bullseye: resolved (fixed in 1:6.6p1-1)
forky: resolved (fixed in 1:6.6p1-1)
sid: resolved (fixed in 1:6.6p1-1)
debian
CVE-2011-0539P3MEDIUMCVSS 5.0fixed in openssh 1:5.8p1-2 (bookworm)2011
CVE-2011-0539 [MEDIUM] CVE-2011-0539: openssh - The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when gener...
The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.
Scope: local
bookworm: resolved (fixed in 1:5.8
debian
CVE-2003-1562P3LOWCVSS 5.0fixed in openssh 1:3.8.1p1-8.sarge.4 (bookworm)2003
CVE-2003-1562 [MEDIUM] CVE-2003-1562: openssh - sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using ...
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerab
debian
CVE-2008-4109P4LOWCVSS 8.1fixed in openssh 1:4.6p1-1 (bookworm)2008
CVE-2008-4109 [HIGH] CVE-2008-4109: openssh - A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 o...
A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists beca
debian
CVE-2012-0814P3LOWCVSS 3.5fixed in openssh 1:5.6p1-1 (bookworm)2012
CVE-2012-0814 [LOW] CVE-2012-0814: openssh - The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 ...
The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite. NOTE: this can cross privilege boundaries becau
debian
CVE-2015-6564P3MEDIUMCVSS 6.9fixed in openssh 1:6.9p1-1 (bookworm)2015
CVE-2015-6564 [MEDIUM] CVE-2015-6564: openssh - Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c...
Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.
Scope: local
bookworm: resolved (fixed in 1:6.9p1-1)
bullseye: resolved (fixed in 1:6.9
debian
CVE-2016-1907P4MEDIUMCVSS 5.3fixed in openssh 1:7.1p2-1 (bookworm)2016
CVE-2016-1907 [MEDIUM] CVE-2016-1907: openssh - The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows re...
The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic.
Scope: local
bookworm: resolved (fixed in 1:7.1p2-1)
bullseye: resolved (fixed in 1:7.1p2-1)
forky: resolved (fixed in 1:7.1p2-1)
sid: resolved (fixed in 1:7.1p2-1)
trixie:
debian
CVE-2003-0386P4HIGHCVSS 7.5fixed in openssh 1:3.8p1-1 (bookworm)2003
CVE-2003-0386 [HIGH] CVE-2003-0386: openssh - OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses ...
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.
Scope: local
bookworm: resolved (fixed in 1:3.8p1-1)
bullseye: resolved (
debian
CVE-2014-2532P4MEDIUMCVSS 4.9fixed in openssh 1:6.6p1-1 (bookworm)2014
CVE-2014-2532 [MEDIUM] CVE-2014-2532: openssh - sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv line...
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
Scope: local
bookworm: resolved (fixed in 1:6.6p1-1)
bullseye: resolved (fixed in 1:6.6p1-1)
forky: resolved (fixed in 1:6.6p1-1)
sid: res
debian
CVE-2017-15906P4LOWCVSS 5.3fixed in openssh 1:7.6p1-1 (bookworm)2017
CVE-2017-15906 [MEDIUM] CVE-2017-15906: openssh - The process_open function in sftp-server.c in OpenSSH before 7.6 does not proper...
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
Scope: local
bookworm: resolved (fixed in 1:7.6p1-1)
bullseye: resolved (fixed in 1:7.6p1-1)
forky: resolved (fixed in 1:7.6p1-1)
sid: resolved (fixed in 1:7.6p1-1)
trixie: resolved (fixed
debian
CVE-2013-4548P4MEDIUMCVSS 6.0fixed in openssh 1:6.4p1-1 (bookworm)2013
CVE-2013-4548 [MEDIUM] CVE-2013-4548: openssh - The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6...
The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.
Scope: local
bookworm:
debian
CVE-2003-0695P4CRITICALCVSS 10.0fixed in openssh 1:3.7.1 (bookworm)2003
CVE-2003-0695 [CRITICAL] CVE-2003-0695: openssh - Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers ...
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.
Scope: local
bookworm: resolved (fixed in 1:3.7.1)
bullseye: resolved (fixed in
debian
CVE-2015-5352P4MEDIUMCVSS 4.3fixed in openssh 1:6.9p1-1 (bookworm)2015
CVE-2015-5352 [MEDIUM] CVE-2015-5352: openssh - The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when Fo...
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
Scope: local
bookworm: resolved (fixed in 1:6.9p1-1)
bullsey
debian
CVE-2003-0682P4HIGHCVSS 7.5fixed in openssh 1:3.6.1p2-9 (bookworm)2003
CVE-2003-0682 [HIGH] CVE-2003-0682: openssh - "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set...
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
Scope: local
bookworm: resolved (fixed in 1:3.6.1p2-9)
bullseye: resolved (fixed in 1:3.6.1p2-9)
forky: resolved (fixed in 1:3.6.1p2-9)
sid: resolved (fixed in 1:3.6.1p2-9)
trixie: resolved (fixed in 1:3.6.1p2-9)
debian
CVE-2004-2760P4LOWCVSS 5.0fixed in openssh 1:3.6p1-1 (bookworm)2004
CVE-2004-2760 [MEDIUM] CVE-2004-2760: openssh - sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the ...
sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2003-019
debian
CVE-2001-1507P4HIGHCVSS 7.5fixed in openssh 1:3.0.1 (bookworm)2001
CVE-2001-1507 [HIGH] CVE-2001-1507: openssh - OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate user...
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
Scope: local
bookworm: resolved (fixed in 1:3.0.1)
bullseye: resolved (fixed in 1:3.0.1)
forky: resolved (fixed in 1:3.0.1)
sid: resolved (fixed in 1:3.0.1)
trixie: resolved (fixed in 1:3.0.1)
debian