Debian OpenSSH vulnerabilities

115 known vulnerabilities affecting debian/openssh.

Total CVEs
115
CISA KEV
0
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH21MEDIUM25LOW64

Vulnerabilities

Page 5 of 6
CVE-2006-0883MEDIUMCVSS 5.0fixed in openssh 1:3.8.1p1-4 (bookworm)2006
CVE-2006-0883 [MEDIUM] CVE-2006-0883: openssh - OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle... OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting. Scope: local bookworm: resolved (
debian
CVE-2006-4924LOWCVSS 7.8PoCfixed in openssh 1:4.3p2-4 (bookworm)2006
CVE-2006-4924 [HIGH] CVE-2006-4924: openssh - sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote... sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector. Scope: local bookworm: resolved (fixed in 1:4.3p2-4) bullseye: resolved (fixed in 1:4.3p2-4) forky: resolved (f
debian
CVE-2006-5794LOWCVSS 7.5fixed in openssh 1:4.3p2-6 (bookworm)2006
CVE-2006-5794 [HIGH] CVE-2006-5794: openssh - Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH be... Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exis
debian
CVE-2006-5052LOWCVSS 5.0fixed in openssh 1:4.6p1-1 (bookworm)2006
CVE-2006-5052 [MEDIUM] CVE-2006-5052: openssh - Unspecified vulnerability in portable OpenSSH before 4.4, when running on some p... Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort." Scope: local bookworm: resolved (fixed in 1:4.6p1-1) bullseye: resolved (fixed in 1:4.6p1-1) forky: resolved (fixed in 1:4.6p1-1) sid: resolved (fixed i
debian
CVE-2006-4925LOWCVSS 5.0fixed in openssh 1:5.1p1-5 (bookworm)2006
CVE-2006-4925 [MEDIUM] CVE-2006-4925: openssh - packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service ... packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL. Scope: local bookworm: resolved (fixed in 1:5.1p1-5) bullseye: resolved (fixed in 1:5.1p1-5) forky: resolved (fixed in 1:5.1p1-5) sid: resolved (fixed in 1:5.1p1-5
debian
CVE-2006-0225LOWCVSS 4.6fixed in dropbear 0.48-1 (bookworm)2006
CVE-2006-0225 [MEDIUM] CVE-2006-0225: dropbear - scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filename... scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice. Scope: local bookworm: resolved (fixed in 0.48-1) bullseye: resolved (fixed in 0.48-1) forky: resolved (fixed in 0.48-1) sid: resolved (fixed in 0.48-1) trixie: resolved (fixed in 0.48-1)
debian
CVE-2006-5051LOWCVSS 8.1fixed in openssh 1:4.6p1-1 (bookworm)2006
CVE-2006-5051 [HIGH] CVE-2006-5051: openssh - Signal handler race condition in OpenSSH before 4.4 allows remote attackers to c... Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free. Scope: local bookworm: resolved (fixed in 1:4.6p1-1) bullseye: resolved (fixed in 1:4.6p1-1) forky: resolved (fixed in 1:4.6p1-1) s
debian
CVE-2005-2797LOWCVSS 5.0fixed in openssh 1:4.2p1-1 (bookworm)2005
CVE-2005-2797 [MEDIUM] CVE-2005-2797: openssh - OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic por... OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, which may cause OpenSSH to enable the GatewayPorts functionality. Scope: local bookworm: resolved (fixed in 1:4.2p1-1) bullseye: resolved (fixed in 1:4.2p1-1) forky: resolved (fixed in 1:4.2p1-1) sid: resolved (fixed in 1:
debian
CVE-2005-2798LOWCVSS 5.0fixed in openssh 1:4.2p1-1 (bookworm)2005
CVE-2005-2798 [MEDIUM] CVE-2005-2798: openssh - sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GS... sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts. Scope: local bookworm: resolved (fixed in 1:4.2p1-1) bullseye: resolved (fixed in 1:4.2p1-1) forky: resolved (fixed in 1:4.2p1-1
debian
CVE-2005-2666LOWCVSS 1.2fixed in openssh 1:4.0p1-1 (bookworm)2005
CVE-2005-2666 [LOW] CVE-2005-2666: openssh - SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, st... SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a list of additional targets that are more likely to have the same password or key. Scope: local bookworm: resolved (fixe
debian
CVE-2004-2069MEDIUMCVSS 5.0fixed in openssh 1:3.8p1 (bookworm)2004
CVE-2004-2069 [MEDIUM] CVE-2004-2069: openssh - sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using pr... sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption). Scope: local bookworm
debian
CVE-2004-0175LOWCVSS 5.0fixed in openssh 1:3.9p1-1 (bookworm)2004
CVE-2004-0175 [MEDIUM] CVE-2004-0175: openssh - Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote ... Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992. Scope: local bookworm: resolved (fixed in 1:3.9p1-1) bullseye: resolved (fixed in 1:3.9p1-1) forky: resolved (fixed in 1:3.9p1-1) sid: resolved (fixed in 1:3.9p1-1) trixie: resolved (fixed i
debian
CVE-2004-1653LOWCVSS 6.42004
CVE-2004-1653 [MEDIUM] CVE-2004-1653: openssh - The default configuration for OpenSSH enables AllowTcpForwarding, which could al... The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2004-2760LOWCVSS 5.0fixed in openssh 1:3.6p1-1 (bookworm)2004
CVE-2004-2760 [MEDIUM] CVE-2004-2760: openssh - sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the ... sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2003-019
debian
CVE-2003-0693CRITICALCVSS 10.0fixed in openssh 1:3.6.1p2-6.0 (bookworm)2003
CVE-2003-0693 [CRITICAL] CVE-2003-0693: openssh - A "buffer management error" in buffer_append_space of buffer.c for OpenSSH befor... A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695. Scope: local bookworm: resolved (fixed in 1:3.6.1p2-6.0) bullseye: resolved (fixed in 1:3.6.1p2-6.0) fo
debian
CVE-2003-0786CRITICALCVSS 10.0fixed in openssh 1:3.7.1p2 (bookworm)2003
CVE-2003-0786 [CRITICAL] CVE-2003-0786: openssh - The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, whe... The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges. Scope: local bookworm: resolved (fixed in 1:3.7.1p2) bullseye: resolved (fixed in 1:3.7.1p2) forky: resolved (fixed in 1:3.7.1p2) sid: resol
debian
CVE-2003-0695CRITICALCVSS 10.0fixed in openssh 1:3.7.1 (bookworm)2003
CVE-2003-0695 [CRITICAL] CVE-2003-0695: openssh - Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers ... Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693. Scope: local bookworm: resolved (fixed in 1:3.7.1) bullseye: resolved (fixed in
debian
CVE-2003-0787HIGHCVSS 7.5fixed in openssh 1:3.7.1p2 (bookworm)2003
CVE-2003-0787 [HIGH] CVE-2003-0787: openssh - The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array o... The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges. Scope: local bookworm: resolved (fixed in 1:3.7.1p2) bullseye: resolved (fixed in 1:3.7.1p2) forky: resolved (fixed in 1:3.7.1p2) sid: resolved (fixed in 1:3.7.1p2) trixie: resolv
debian
CVE-2003-0386HIGHCVSS 7.5fixed in openssh 1:3.8p1-1 (bookworm)2003
CVE-2003-0386 [HIGH] CVE-2003-0386: openssh - OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses ... OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address. Scope: local bookworm: resolved (fixed in 1:3.8p1-1) bullseye: resolved (
debian
CVE-2003-0682HIGHCVSS 7.5fixed in openssh 1:3.6.1p2-9 (bookworm)2003
CVE-2003-0682 [HIGH] CVE-2003-0682: openssh - "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set... "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695. Scope: local bookworm: resolved (fixed in 1:3.6.1p2-9) bullseye: resolved (fixed in 1:3.6.1p2-9) forky: resolved (fixed in 1:3.6.1p2-9) sid: resolved (fixed in 1:3.6.1p2-9) trixie: resolved (fixed in 1:3.6.1p2-9)
debian