PT-1998-1197 · Openssh · Ssh
Published
1998-11-05
·
Updated
2008-09-05
·
CVE-1999-1321
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ssh version 1.2.26
Description
A buffer overflow issue exists in the ssh client when Kerberos V is enabled. This could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.
Recommendations
For ssh version 1.2.26, consider disabling Kerberos V support as a temporary workaround until a patch is available. Restrict access to the ssh client to minimize the risk of exploitation. Avoid using long DNS hostnames in the ssh client until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ssh