CVE-2008-4109 is a denial-of-service vulnerability affecting specific Debian OpenSSH versions and other distributions like SUSE. It stems from an incorrect fix for a previous CVE, where non-async-signal-safe functions were used in the signal handler for login timeouts. This allows remote attackers to exhaust connection slots through multiple login attempts. The vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and no authentication required, leading to a partial denial of service. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available for this specific CVE. Despite its age, it has garnered significant community discussion and media coverage, though some of the linked articles appear to be discussing a different, more recent OpenSSH vulnerability (CVE-2024-6387) rather than CVE-2008-4109.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3p2CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:1.2:*:*:*:*:*:*:* | ||
1.2.1CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:1.2.1:*:*:*:*:*:*:* | ||
1.2.2CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:1.2.2:*:*:*:*:*:*:* | ||
1.2.3CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:1.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.