VDB
CVE-2005-2798
CVE-2005-2798
PUBLISHED
CVSS 5 MEDIUM
sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.
EPSS 2.30% · 81.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.30%
81.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openbsd | openssh | 3.5, 3.0, 3.0.1 |
| n/a | n/a | * |
Timeline
- Sep 6, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- 17245 third-party-advisory
- [openssh-unix-announce] 20050901 Announce: OpenSSH 4.2 released mailing-list
- hpux-secure-shell-dos(24064) vdb
- SCOSA-2005.53 vendor-advisory
- 18507 third-party-advisory
- 19141 vdb
- SSRT051058 vendor-advisory
- 18717 third-party-advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-016.htm url
- MDKSA-2005:172 vendor-advisory
- USN-209-1 vendor-advisory
- 16686 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-2798 advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1345 url
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9717 url
- https://usn.ubuntu.com/209-1 url
- http://secunia.com/advisories/18406 url
- http://secunia.com/advisories/18661 url
- http://www.redhat.com/support/errata/RHSA-2005-527.html url
- http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html technical
…and 7 more