CVE-2010-5107

The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.

high 7.5 CVSS 3.1
Published: Mar 7, 2013
Modified: May 29, 2026
Vendor: Openbsd
Product: Openssh
Versions: 1.2,1.2.1,1.2.2,1.2.3,1.2.27,1.3,1.5,1.5.7,1.5.8,2.1

Description

The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.

References

Related CVEs