PT-2013-1004 · Check Point+7 · Check Point Gaia+7

Jan Lieskovsky

·

Published

2013-02-06

·

Updated

2026-05-29

·

CVE-2010-5107

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 6.6 p1-r1 OpenSSH through 6.1 VMware vCenter Server (affected versions not specified) Check Point GAiA (affected versions not specified)
Description The issue is related to a mechanism in OpenSSH that can cause a denial of service when the authentication procedure is performed, especially if the logingracetime and maxstartup values differ from their default settings. By increasing the number of requests to the service, a remote attacker can prevent other users from logging in. The default configuration of OpenSSH enforces a fixed time limit between establishing a TCP connection and completing a login, making it easier for remote attackers to cause a denial of service by periodically making many new TCP connections. Multiple vulnerabilities in the OpenSSH package can lead to violations of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations For OpenSSH versions prior to 6.6 p1-r1, update to version 6.6 p1-r1 or later to resolve the issue. For OpenSSH through 6.1, consider increasing the connection timeout value to mitigate the risk of connection-slot exhaustion. For VMware vCenter Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Check Point GAiA, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Information Disclosure

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1351
ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2014-00019
BDU:2015-09678
CESA-2013_1591
CVE-2010-5107
RHSA-2013:1527
RHSA-2013:1591
RHSA-2013_1591
SUSE-SU-2013_1345-1

Affected Products

Alt Linux
Centos
Check Point Gaia
Ibm Aix
Openssh
Red Hat
Suse
Vmware Vcenter Server