PT-2006-1032 · Openssh+4 · Openssh+8

Tavis Ormandy

·

Published

2006-09-27

·

Updated

2025-04-09

·

CVE-2006-4924

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSH versions prior to 4.4 OpenSSH version 3.1p1 openssh-askpass versions prior to 4.3 p2-r5 openssh-askpass-gnome version 3.1p1 openssh-clients version 3.1p1 openssh-server version 3.1p1
Description: The issue concerns multiple vulnerabilities in the OpenSSH package, which can lead to disruptions in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The problem affects various versions of OpenSSH, including those used in openSUSE and Red Hat Enterprise Linux operating systems. In one specific case, the vulnerability in OpenSSH before version 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service via an SSH packet containing duplicate blocks that are not properly handled by the CRC compensation attack detector.
Recommendations: For OpenSSH versions prior to 4.4, update to version 4.4 or later. For OpenSSH version 3.1p1, consider upgrading to a newer version or applying available patches. For openssh-askpass versions prior to 4.3 p2-r5, update to version 4.3 p2-r5 or later. For openssh-askpass-gnome version 3.1p1, openssh-clients version 3.1p1, and openssh-server version 3.1p1, consider upgrading to newer versions or applying available patches. As a temporary workaround, consider restricting access to the vulnerable OpenSSH components until a patch is available.

Exploit

Fix

DoS

Double Free

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-04932
BDU:2015-06465
BDU:2015-06467
BDU:2015-06469
BDU:2015-06471
BDU:2015-06473
BDU:2015-09536
CVE-2006-4924
DSA-1189-1
DSA-1212
HPSBUX02178
RHSA-2006:0697
RHSA-2006:0698
RHSA-2006_0697

Affected Products

Alt Linux
Hp-Ux
Openssh
Red Hat
Opensuse
Openssh-Askpass
Openssh-Askpass-Gnome
Openssh-Clients
Openssh-Server