cbcvebase.

Debian OpenSSH vulnerabilities

83 known vulnerabilities affecting debian/openssh.

Total CVEs
83
CISA KEV
0
Public exploits
16
Exploited in wild
8
Severity breakdown
CRITICAL5HIGH20MEDIUM24LOW34

Vulnerabilities

Page 4 of 5
CVE-2001-1459P4HIGHCVSS 7.5fixed in openssh 1:3.0.1p1-1 (bookworm)2001
CVE-2001-1459 [HIGH] CVE-2001-1459: openssh - OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM... OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d. Scope: local bookworm: resolved (fixed in 1:3.0.1p1-1) bullseye: resolved (fixed in 1:3.0.1p1-1) forky: resolved (fixed in 1:3.0.1p1-1) sid: resolved (fixed in 1:3.0.1
debian
CVE-2003-0787P4HIGHCVSS 7.5fixed in openssh 1:3.7.1p2 (bookworm)2003
CVE-2003-0787 [HIGH] CVE-2003-0787: openssh - The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array o... The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges. Scope: local bookworm: resolved (fixed in 1:3.7.1p2) bullseye: resolved (fixed in 1:3.7.1p2) forky: resolved (fixed in 1:3.7.1p2) sid: resolved (fixed in 1:3.7.1p2) trixie: resolv
debian
CVE-2008-1657P4LOWCVSS 6.5fixed in openssh 1:4.7p1-8 (bookworm)2008
CVE-2008-1657 [MEDIUM] CVE-2008-1657: openssh - OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypas... OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file. Scope: local bookworm: resolved (fixed in 1:4.7p1-8) bullseye: resolved (fixed in 1:4.7p1-8) forky: resolved (fixed in 1:4.7p1-8) sid: resolved (fixed in 1:4.7p1-8) trixie: resolved (fixed in 1:4.7p1-8)
debian
CVE-2006-5052P4LOWCVSS 5.0fixed in openssh 1:4.6p1-1 (bookworm)2006
CVE-2006-5052 [MEDIUM] CVE-2006-5052: openssh - Unspecified vulnerability in portable OpenSSH before 4.4, when running on some p... Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort." Scope: local bookworm: resolved (fixed in 1:4.6p1-1) bullseye: resolved (fixed in 1:4.6p1-1) forky: resolved (fixed in 1:4.6p1-1) sid: resolved (fixed i
debian
CVE-2006-4925P4LOWCVSS 5.0fixed in openssh 1:5.1p1-5 (bookworm)2006
CVE-2006-4925 [MEDIUM] CVE-2006-4925: openssh - packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service ... packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL. Scope: local bookworm: resolved (fixed in 1:5.1p1-5) bullseye: resolved (fixed in 1:5.1p1-5) forky: resolved (fixed in 1:5.1p1-5) sid: resolved (fixed in 1:5.1p1-5
debian
CVE-2006-0225P4LOWCVSS 4.6fixed in dropbear 0.48-1 (bookworm)2006
CVE-2006-0225 [MEDIUM] CVE-2006-0225: dropbear - scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filename... scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice. Scope: local bookworm: resolved (fixed in 0.48-1) bullseye: resolved (fixed in 0.48-1) forky: resolved (fixed in 0.48-1) sid: resolved (fixed in 0.48-1) trixie: resolved (fixed in 0.48-1)
debian
CVE-2015-6563P4LOWCVSS 1.9fixed in openssh 1:6.9p1-1 (bookworm)2015
CVE-2015-6563 [LOW] CVE-2015-6563: openssh - The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms acc... The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c.
debian
CVE-2002-0765P4HIGHCVSS 7.5fixed in openssh 1:3.3p1-0.0woody1 (bookworm)2002
CVE-2002-0765 [HIGH] CVE-2002-0765: openssh - sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions... sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password. Scope: local bookworm: resolved (fixed in 1:3.3p1-0.0woody1) bullseye: resolved (fixed in 1:3.3p1-0.0woody1) forky: resolved (fixed in 1:3.3p1-0.0woody1) sid: resolved (fixed in 1:3.3p1-0.0woody1) trixi
debian
CVE-2006-0883P4MEDIUMCVSS 5.0fixed in openssh 1:3.8.1p1-4 (bookworm)2006
CVE-2006-0883 [MEDIUM] CVE-2006-0883: openssh - OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle... OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting. Scope: local bookworm: resolved (
debian
CVE-2023-51384P4MEDIUMCVSS 5.5fixed in openssh 1:9.2p1-2+deb12u2 (bookworm)2023
CVE-2023-51384 [MEDIUM] CVE-2023-51384: openssh - In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incom... In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys. Scope: local bookworm: resolved (fixed in 1:9.2p1-2+deb12u2) bullseye: resolve
debian
CVE-2016-10011P4LOWCVSS 5.5fixed in openssh 1:7.4p1-1 (bookworm)2016
CVE-2016-10011 [MEDIUM] CVE-2016-10011: openssh - authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects ... authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process. Scope: local bookworm: resolved (fixed in 1:7.4p1-1) bullseye: resolved (fixed in 1:7.4p1-1) forky: resolved (fixed in 1
debian
CVE-2008-2285P4HIGHCVSS 7.5fixed in openssh 1:4.7p1-10 (bookworm)2008
CVE-2008-2285 [HIGH] CVE-2008-2285: openssh - The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize... The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool. Scope: local bookworm: resolved (fixed in 1:4.7p1-10) bullseye: resolved (fixed in 1:4.7p1-10) forky: resolved (fixed in
debian
CVE-2021-36368P4LOWCVSS 3.7fixed in openssh 1:8.9p1-1 (bookworm)2021
CVE-2021-36368 [LOW] CVE-2021-36368: openssh - An issue was discovered in OpenSSH before 8.9. If a client is using public-key a... An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or
debian
CVE-2004-0175P4LOWCVSS 5.0fixed in openssh 1:3.9p1-1 (bookworm)2004
CVE-2004-0175 [MEDIUM] CVE-2004-0175: openssh - Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote ... Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992. Scope: local bookworm: resolved (fixed in 1:3.9p1-1) bullseye: resolved (fixed in 1:3.9p1-1) forky: resolved (fixed in 1:3.9p1-1) sid: resolved (fixed in 1:3.9p1-1) trixie: resolved (fixed i
debian
CVE-2004-2069P4MEDIUMCVSS 5.0fixed in openssh 1:3.8p1 (bookworm)2004
CVE-2004-2069 [MEDIUM] CVE-2004-2069: openssh - sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using pr... sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption). Scope: local bookworm
debian
CVE-2005-2798P4LOWCVSS 5.0fixed in openssh 1:4.2p1-1 (bookworm)2005
CVE-2005-2798 [MEDIUM] CVE-2005-2798: openssh - sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GS... sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts. Scope: local bookworm: resolved (fixed in 1:4.2p1-1) bullseye: resolved (fixed in 1:4.2p1-1) forky: resolved (fixed in 1:4.2p1-1
debian
CVE-2005-2797P4LOWCVSS 5.0fixed in openssh 1:4.2p1-1 (bookworm)2005
CVE-2005-2797 [MEDIUM] CVE-2005-2797: openssh - OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic por... OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, which may cause OpenSSH to enable the GatewayPorts functionality. Scope: local bookworm: resolved (fixed in 1:4.2p1-1) bullseye: resolved (fixed in 1:4.2p1-1) forky: resolved (fixed in 1:4.2p1-1) sid: resolved (fixed in 1:
debian
CVE-2025-61984P4LOWCVSS 3.6fixed in openssh 1:9.2p1-2+deb12u8 (bookworm)2025
CVE-2025-61984 [LOW] CVE-2025-61984: openssh - ssh in OpenSSH before 10.1 allows control characters in usernames that originate... ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as a
debian
CVE-2008-1483P4MEDIUMCVSS 6.9fixed in openssh 1:4.7p1-5 (bookworm)2008
CVE-2008-1483 [MEDIUM] CVE-2008-1483: openssh - OpenSSH 4.3p2, and probably other versions, allows local users to hijack forward... OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs. Scope: local bookworm: resolved (fixed in 1:4.7p1-5) bullseye: resolved (fixed in 1:4
debian
CVE-2025-32728P4MEDIUMCVSS 4.3fixed in openssh 1:9.2p1-2+deb12u6 (bookworm)2025
CVE-2025-32728 [MEDIUM] CVE-2025-32728: openssh - In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere ... In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding. Scope: local bookworm: resolved (fixed in 1:9.2p1-2+deb12u6) bullseye: resolved (fixed in 1:8.4p1-5+deb11u5) forky: resolved (fixed in 1:10.0p1-1) sid: resolved (fixed in 1:10.0p1-1) trixie: resolved (fixed in 1:10
debian
Debian OpenSSH vulnerabilities | cvebase