PT-2006-7542 · Openssh+2 · Ssh+8

Mark Dowd

·

Published

1970-01-01

·

Updated

2025-09-30

·

CVE-2006-5051

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openssh versions prior to 4.4 p1-r5 openssh-server-udeb (affected versions not specified) openssh-server-3.1p1 (affected versions not specified) openssh-clients-3.1p1 (affected versions not specified) openssh-client-udeb (affected versions not specified) openssh-3.1p1 (affected versions not specified) openssh-askpass-3.1p1 (affected versions not specified) openssh-askpass-gnome-3.1p1 (affected versions not specified) openssh-askpass (affected versions not specified) ssh (affected versions not specified) ssh-krb5 (affected versions not specified) openssh-server (affected versions not specified) openssh-client (affected versions not specified) openssh-askpass-gnome (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the openssh package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The signal handler race condition in OpenSSH before version 4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code if GSSAPI authentication is enabled.
Recommendations For openssh versions prior to 4.4 p1-r5, update to a version 4.4 p1-r5 or later. For openssh-server-udeb, openssh-server-3.1p1, openssh-clients-3.1p1, openssh-client-udeb, openssh-3.1p1, openssh-askpass-3.1p1, openssh-askpass-gnome-3.1p1, openssh-askpass, ssh, ssh-krb5, openssh-server, openssh-client, and openssh-askpass-gnome, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-01339
BDU:2015-01340
BDU:2015-01958
BDU:2015-01959
BDU:2015-01960
BDU:2015-01961
BDU:2015-01962
BDU:2015-04932
BDU:2015-06465
BDU:2015-06467
BDU:2015-06469
BDU:2015-06471
BDU:2015-06473
BDU:2015-09537
BDU:2024-06777
CVE-2006-5051
DSA-1189-1
DSA-1212
DSA-1638-1
RHSA-2006:0697
RHSA-2006:0698
RHSA-2006_0697

Affected Products

Alt Linux
Openssh
Red Hat
Openssh-Askpass
Openssh-Askpass-Gnome
Openssh-Clients
Openssh-Server
Ssh
Ssh-Krb5