New Search

AIX OpenSSH Vulnerability

oval:org.mitre.oval:def:19515

The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • IBM AIX 6.1
  • IBM AIX 5.3
  • IBM AIX 7.1
Class:
vulnerability
Reference(s):
  • CVE-2010-5107
Product(s):