5
CVSSv2

CVE-2008-0132

Published: 08/01/2008 Updated: 24/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Pragma FortressSSH 5.0 Build 4 Revision 293 and previous versions handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote malicious users to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pragmasys fortress ssh 5.0

pragmasys fortress ssh

Exploits

source: wwwsecurityfocuscom/bid/27141/info Pragma Systems FortressSSH is prone to a remote denial-of-service vulnerability because it fails to adequately handle certain exceptions when processing overly long user-supplied input Attackers can exploit this issue to exhaust the maximum number of connections alotted for servers Successful ...