CVE-2006-5051
Published Sep 27, 2006
·
Last updated 3 months ago
Description
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
Risk scores
CVSS 3.1
- Primary
- 8.1
- 5.9
- 2.2
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- HIGH
CVSS 2.0
- Primary
- 9.3
- 10
- 8.6
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
Source
secalert@redhat.com
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E3FE4E6-870E-4F84-9D50-7BF48ADFB380", "versionEndIncluding": "4.4" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2E0C1F8-31F5-4F61-9DF7-E49B43D3C873" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CE37418-3D19-483A-9ADE-2E38272A4ACC", "versionEndExcluding": "10.3.9" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39D14EF2-E8E0-4021-A493-E822612FFB35", "versionEndIncluding": "10.4.8", "versionStartIncluding": "10.4" }, { "criteria": "cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E9A9D63-EEA1-4289-8382-6CC91D2241A1", "versionEndExcluding": "10.3.9" }, { "criteria": "cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0D26E9A-DF4A-4795-BE74-2196127BB3E7", "versionEndIncluding": "10.4.8", "versionStartIncluding": "10.4" } ], "operator": "OR" } ] } ]