PT-2006-1033 · Openssh+2 · Openssh+2
Mark Dowd
·
Published
2006-09-27
·
Updated
2024-07-08
·
CVE-2006-5052
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
openssh versions prior to 4.4 p1-r5
openssh version prior to 4.4
Description:
The issue involves multiple vulnerabilities in the openssh package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. The exploitation can be carried out via unknown vectors involving a GSSAPI "authentication abort" when running on certain platforms, allowing remote attackers to determine the validity of usernames.
Recommendations:
For openssh versions prior to 4.4 p1-r5, update to version 4.4 p1-r5 or later.
For openssh version prior to 4.4, update to version 4.4 or later.
As a temporary workaround, consider restricting access to the GSSAPI authentication mechanism until a patch is available.
Exploit
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Red Hat
Openssh