PT-2006-1033 · Openssh+2 · Openssh+2

Mark Dowd

·

Published

2006-09-27

·

Updated

2024-07-08

·

CVE-2006-5052

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: openssh versions prior to 4.4 p1-r5 openssh version prior to 4.4
Description: The issue involves multiple vulnerabilities in the openssh package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. The exploitation can be carried out via unknown vectors involving a GSSAPI "authentication abort" when running on certain platforms, allowing remote attackers to determine the validity of usernames.
Recommendations: For openssh versions prior to 4.4 p1-r5, update to version 4.4 p1-r5 or later. For openssh version prior to 4.4, update to version 4.4 or later. As a temporary workaround, consider restricting access to the GSSAPI authentication mechanism until a patch is available.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-04932
BDU:2015-09537
CVE-2006-5052
RHSA-2007:0540
RHSA-2007:0703
RHSA-2007_0540
RHSA-2007_0703

Affected Products

Alt Linux
Red Hat
Openssh