PT-2013-1004 · Check Point+7 · Check Point Gaia+7
Jan Lieskovsky
·
Published
2013-02-06
·
Updated
2026-05-29
·
CVE-2010-5107
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions prior to 6.6 p1-r1
OpenSSH through 6.1
VMware vCenter Server (affected versions not specified)
Check Point GAiA (affected versions not specified)
Description
The issue is related to a mechanism in OpenSSH that can cause a denial of service when the authentication procedure is performed, especially if the logingracetime and maxstartup values differ from their default settings. By increasing the number of requests to the service, a remote attacker can prevent other users from logging in. The default configuration of OpenSSH enforces a fixed time limit between establishing a TCP connection and completing a login, making it easier for remote attackers to cause a denial of service by periodically making many new TCP connections. Multiple vulnerabilities in the OpenSSH package can lead to violations of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations
For OpenSSH versions prior to 6.6 p1-r1, update to version 6.6 p1-r1 or later to resolve the issue.
For OpenSSH through 6.1, consider increasing the connection timeout value to mitigate the risk of connection-slot exhaustion.
For VMware vCenter Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Check Point GAiA, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Buffer Overflow
Information Disclosure
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Check Point Gaia
Ibm Aix
Openssh
Red Hat
Suse
Vmware Vcenter Server