PT-2006-1033 · Openssh+2 · Openssh+2
Mark Dowd
·
Publicado
2006-09-27
·
Atualizado
2024-07-08
·
CVE-2006-5052
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
openssh versions prior to 4.4 p1-r5
openssh version prior to 4.4
Description:
The issue involves multiple vulnerabilities in the openssh package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. The exploitation can be carried out via unknown vectors involving a GSSAPI "authentication abort" when running on certain platforms, allowing remote attackers to determine the validity of usernames.
Recommendations:
For openssh versions prior to 4.4 p1-r5, update to version 4.4 p1-r5 or later.
For openssh version prior to 4.4, update to version 4.4 or later.
As a temporary workaround, consider restricting access to the GSSAPI authentication mechanism until a patch is available.
Exploit
Correção
Double Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Red Hat
Openssh