CVE-2008-4109: Race Condition
A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4109?
CVE-2008-4109 is classified as a denial of service vulnerability affecting OpenSSH.
How do I fix CVE-2008-4109?
To fix CVE-2008-4109, upgrade OpenSSH to version 4.3p2 or later if using Debian or relevant distributions.
What versions of OpenSSH are affected by CVE-2008-4109?
CVE-2008-4109 affects OpenSSH versions prior to 4.3p2, including versions 1.2 through 4.3.
Can CVE-2008-4109 lead to remote exploitation?
No, CVE-2008-4109 does not allow remote execution of code; it only allows denial of service.
Is there a workaround for CVE-2008-4109?
There is no effective workaround for CVE-2008-4109 other than upgrading to a safe version of OpenSSH.