CVE-2010-5107
7.5 HIGHThe default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login...
Published: 2013-03-07 · Last updated: 2026-05-29
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-400
Affected products
| Vendor | Product |
|---|---|
| openbsd | openssh |
Description
The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2010-5107
- [Other]http://marc.info/?l=bugtraq&m=144050155601375&w=2
- [Other]http://rhn.redhat.com/errata/RHSA-2013-1591.html
- [Other]http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/servconf.c?r1=1.234#rev1.234
- [Other]http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config.5?r1=1.156#rev1.156
- [Other]http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config?r1=1.89#rev1.89
- [Other]http://www.openwall.com/lists/oss-security/2013/02/07/3
- [Other]http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- [Other]http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- [Other]http://www.securityfocus.com/bid/58162
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=908707
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19515
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19595
- [Other]http://marc.info/?l=bugtraq&m=144050155601375&w=2
- [Other]http://rhn.redhat.com/errata/RHSA-2013-1591.html
- [Other]http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/servconf.c?r1=1.234#rev1.234
- [Other]http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config.5?r1=1.156#rev1.156
- [Other]http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config?r1=1.89#rev1.89
- [Other]http://www.openwall.com/lists/oss-security/2013/02/07/3
- [Other]http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- [Other]http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- [Other]http://www.securityfocus.com/bid/58162
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=908707
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19515
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19595
Related CVEs
Same vendor
- CVE-2026-3497 — Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions (7.5 HIGH)
- CVE-2023-51767 — OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer ... (7.0 HIGH)
- CVE-2023-51384 — In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied (5.5 MEDIUM)
- CVE-2023-28531 — ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints (9.8 CRITICAL)
- CVE-2023-25136 — OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling (6.5 MEDIUM)
Same CWE
- CVE-2026-12325 — Denial-of-service in the Graphics: ImageLib component (6.5 MEDIUM)
- CVE-2026-12319 — Denial-of-service in the Audio/Video: Playback component (6.5 MEDIUM)
- CVE-2026-50889 — An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending ... (7.5 HIGH)
- CVE-2026-50882 — An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted PO... (7.5 HIGH)
- CVE-2026-50879 — An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a ... (7.5 HIGH)