#VU73777 Out-of-bounds read in OpenSSH
Published: March 17, 2023
OpenSSH
OpenSSH
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the getrrsetbyname(3) function within the VerifyHostKeyDNS feature. A remote attacker can send a specifically crafted DNS response to the ssh client, trigger an out-of-bounds read of adjacent stack data of the ssh client and perform a denial of service (DoS) attack.