Sploitus

CVE-2011-5000

No indexed exploits for CVE-2011-5000 yet

The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.

Affected products
Alt Linux, Centos, Openssh, Red Hat, Suse
Openbsd Openssh
≤ 5.8, 1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.27, 1.3, 1.5, 1.5.7, 1.5.8, 3.0, 3.0.1, 3.0.1p1, 3.0.2, 3.0.2p1, 3.0p1, 3.1, 3.1p1, 3.2, 3.2.2, 3.2.2p1, 3.2.3p1, 3.3, 3.3p1, 3.4, 3.4p1, 3.5, 3.5p1, 3.6, 3.6.1, 3.6.1p1, 3.6.1p2, 3.7, 3.7.1, 3.7.1p1, 3.7.1p2, 3.8, 3.8.1, 3.8.1p1, 3.9
Fix
Available
CVSS 2.0
3.5 LOW
EPSS
2.6% (84th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2012-04-04
CVE-2011-5000 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2011-5000 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2011-5000 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.