CVE-2006-5051

Published Sep 27, 2006

Last updated 3 months ago

Modified

Description

Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.

Risk scores

CVSS 3.1

Primary
8.1
5.9
2.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
HIGH

CVSS 2.0

Primary
9.3
10
8.6
AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-415

Source

secalert@redhat.com

Configurations

References