PT-2006-1033 · Openssh+2 · Openssh+2

Mark Dowd

·

Publicado

2006-09-27

·

Atualizado

2024-07-08

·

CVE-2006-5052

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: openssh versions prior to 4.4 p1-r5 openssh version prior to 4.4
Description: The issue involves multiple vulnerabilities in the openssh package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. The exploitation can be carried out via unknown vectors involving a GSSAPI "authentication abort" when running on certain platforms, allowing remote attackers to determine the validity of usernames.
Recommendations: For openssh versions prior to 4.4 p1-r5, update to version 4.4 p1-r5 or later. For openssh version prior to 4.4, update to version 4.4 or later. As a temporary workaround, consider restricting access to the GSSAPI authentication mechanism until a patch is available.

Exploit

Correção

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-04932
BDU:2015-09537
CVE-2006-5052
RHSA-2007:0540
RHSA-2007:0703
RHSA-2007_0540
RHSA-2007_0703

Produtos afetados

Alt Linux
Red Hat
Openssh