5
CVSSv2

CVE-2005-2798

Published: 06/09/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

sshd in OpenSSH prior to 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh 3.1p1

openbsd openssh 3.2

openbsd openssh 3.5

openbsd openssh 3.5p1

openbsd openssh 3.7.1p2

openbsd openssh 3.8

openbsd openssh 3.8.1

openbsd openssh 3.0

openbsd openssh 3.0.1

openbsd openssh 3.0.1p1

openbsd openssh 3.2.2p1

openbsd openssh 3.2.3p1

openbsd openssh 3.6

openbsd openssh 3.6.1

openbsd openssh 3.8.1p1

openbsd openssh 3.9

openbsd openssh 3.0p1

openbsd openssh 3.1

openbsd openssh 3.4

openbsd openssh 3.4p1

openbsd openssh 3.7

openbsd openssh 3.7.1

openbsd openssh 4.0p1

openbsd openssh 4.1p1

openbsd openssh 3.0.2

openbsd openssh 3.0.2p1

openbsd openssh 3.3

openbsd openssh 3.3p1

openbsd openssh 3.6.1p1

openbsd openssh 3.6.1p2

openbsd openssh 3.9.1

openbsd openssh 3.9.1p1

Vendor Advisories

Synopsis openssh security update Type/Severity Security Advisory: Moderate Topic Updated openssh packages that fix a security issue, bugs, and add supportfor recording login user IDs for audit are now available for Red HatEnterprise Linux 4This update has been rated as having moderate security impact by t ...
An information disclosure vulnerability has been found in the SSH server When the GSSAPIAuthentication option was enabled, the SSH server could send GSSAPI credentials even to users who attempted to log in with a method other than GSSAPI This could inadvertently expose these credentials to an untrusted user ...