PT-1998-1197 · Openssh · Ssh

Published

1998-11-05

·

Updated

2008-09-05

·

CVE-1999-1321

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ssh version 1.2.26
Description A buffer overflow issue exists in the ssh client when Kerberos V is enabled. This could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.
Recommendations For ssh version 1.2.26, consider disabling Kerberos V support as a temporary workaround until a patch is available. Restrict access to the ssh client to minimize the risk of exploitation. Avoid using long DNS hostnames in the ssh client until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1321

Affected Products

Ssh