Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 00:17
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:22.openssh.asc - Broken Link | |
References | () ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc - Broken Link | |
References | () http://docs.info.apple.com/article.html?artnum=305214 - Broken Link | |
References | () http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html - Mailing List | |
References | () http://lists.freebsd.org/pipermail/freebsd-security/2006-October/004051.html - Mailing List | |
References | () http://marc.info/?l=openssh-unix-dev&m=115939141729160&w=2 - Mailing List | |
References | () http://openssh.org/txt/release-4.4 - Release Notes | |
References | () http://secunia.com/advisories/22158 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22173 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22183 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22196 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22208 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22236 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22245 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22270 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22352 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22362 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22487 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22495 - Broken Link | |
References | () http://secunia.com/advisories/22823 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/22926 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/23680 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/24479 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/24799 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/24805 - Broken Link, Vendor Advisory | |
References | () http://security.freebsd.org/advisories/FreeBSD-SA-06%3A22.openssh.asc - Third Party Advisory | |
References | () http://security.gentoo.org/glsa/glsa-200611-06.xml - Third Party Advisory | |
References | () http://securitytracker.com/id?1016940 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.592566 - Broken Link | |
References | () http://sourceforge.net/forum/forum.php?forum_id=681763 - Broken Link | |
References | () http://support.avaya.com/elmodocs2/security/ASA-2006-216.htm - Third Party Advisory | |
References | () http://www-unix.globus.org/mail_archive/security-announce/2007/04/msg00000.html - Broken Link | |
References | () http://www.arkoon.fr/upload/alertes/36AK-2006-07-FR-1.0_FAST360_OPENSSH.pdf - Broken Link | |
References | () http://www.arkoon.fr/upload/alertes/43AK-2006-09-FR-1.0_SSL360_OPENSSH.pdf - Broken Link | |
References | () http://www.debian.org/security/2006/dsa-1189 - Mailing List | |
References | () http://www.debian.org/security/2006/dsa-1212 - Broken Link | |
References | () http://www.kb.cert.org/vuls/id/851340 - Third Party Advisory, US Government Resource | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2006:179 - Third Party Advisory | |
References | () http://www.novell.com/linux/security/advisories/2006_62_openssh.html - Broken Link | |
References | () http://www.openbsd.org/errata.html#ssh - Release Notes | |
References | () http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.022-openssh.html - Broken Link | |
References | () http://www.openwall.com/lists/oss-security/2024/07/01/3 - | |
References | () http://www.openwall.com/lists/oss-security/2024/07/28/3 - | |
References | () http://www.osvdb.org/29264 - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2006-0697.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2006-0698.html - Broken Link | |
References | () http://www.securityfocus.com/bid/20241 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/usn-355-1 - Broken Link | |
References | () http://www.us-cert.gov/cas/techalerts/TA07-072A.html - Third Party Advisory, US Government Resource | |
References | () http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html - Broken Link | |
References | () http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html - Broken Link | |
References | () http://www.vupen.com/english/advisories/2006/4018 - Broken Link | |
References | () http://www.vupen.com/english/advisories/2006/4329 - Broken Link | |
References | () http://www.vupen.com/english/advisories/2007/0930 - Broken Link | |
References | () http://www.vupen.com/english/advisories/2007/1332 - Broken Link | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/29254 - Third Party Advisory, VDB Entry | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11387 - Broken Link | |
References | () https://www.openwall.com/lists/oss-security/2024/07/28/3 - |
29 Jul 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Jul 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Jul 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Feb 2024, 15:36
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-415 | |
References | (SECUNIA) http://secunia.com/advisories/22173 - Broken Link, Vendor Advisory | |
References | (SECUNIA) http://secunia.com/advisories/22208 - Broken Link, Vendor Advisory | |
References | (SECTRACK) http://securitytracker.com/id?1016940 - Broken Link, Third Party Advisory, VDB Entry | |
References | (CERT-VN) http://www.kb.cert.org/vuls/id/851340 - Third Party Advisory, US Government Resource | |
References | (SECUNIA) http://secunia.com/advisories/23680 - Broken Link, Vendor Advisory | |
References | (CONFIRM) http://www.arkoon.fr/upload/alertes/43AK-2006-09-FR-1.0_SSL360_OPENSSH.pdf - Broken Link | |
References | (SUSE) http://www.novell.com/linux/security/advisories/2006_62_openssh.html - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/22487 - Broken Link, Vendor Advisory | |
References | (OSVDB) http://www.osvdb.org/29264 - Broken Link | |
References | (CONFIRM) http://www.arkoon.fr/upload/alertes/36AK-2006-07-FR-1.0_FAST360_OPENSSH.pdf - Broken Link | |
References | (VUPEN) http://www.vupen.com/english/advisories/2007/0930 - Broken Link | |
References | (DEBIAN) http://www.debian.org/security/2006/dsa-1189 - Mailing List | |
References | (CONFIRM) http://support.avaya.com/elmodocs2/security/ASA-2006-216.htm - Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/24799 - Broken Link, Vendor Advisory | |
References | (UBUNTU) http://www.ubuntu.com/usn/usn-355-1 - Broken Link | |
References | (APPLE) http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html - Mailing List | |
References | (SGI) ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc - Broken Link | |
References | (CERT) http://www.us-cert.gov/cas/techalerts/TA07-072A.html - Third Party Advisory, US Government Resource | |
References | (MLIST) http://lists.freebsd.org/pipermail/freebsd-security/2006-October/004051.html - Mailing List | |
References | (SECUNIA) http://secunia.com/advisories/22236 - Broken Link, Vendor Advisory | |
References | (SECUNIA) http://secunia.com/advisories/22926 - Broken Link, Vendor Advisory | |
References | (MLIST) http://www-unix.globus.org/mail_archive/security-announce/2007/04/msg00000.html - Broken Link | |
References | (MLIST) http://marc.info/?l=openssh-unix-dev&m=115939141729160&w=2 - Mailing List | |
References | (SECUNIA) http://secunia.com/advisories/22495 - Broken Link | |
References | (CONFIRM) http://sourceforge.net/forum/forum.php?forum_id=681763 - Broken Link | |
References | (CONFIRM) http://openssh.org/txt/release-4.4 - Release Notes | |
References | (VUPEN) http://www.vupen.com/english/advisories/2007/1332 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/22245 - Broken Link, Vendor Advisory | |
References | (SECUNIA) http://secunia.com/advisories/22823 - Broken Link, Vendor Advisory | |
References | (FREEBSD) ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:22.openssh.asc - Broken Link | |
References | (BID) http://www.securityfocus.com/bid/20241 - Broken Link, Third Party Advisory, VDB Entry | |
References | (CONFIRM) http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html - Broken Link | |
References | (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDKSA-2006:179 - Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/22270 - Broken Link, Vendor Advisory | |
References | (OPENBSD) http://www.openbsd.org/errata.html#ssh - Release Notes | |
References | (CONFIRM) http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html - Broken Link | |
References | (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11387 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/22158 - Broken Link, Vendor Advisory | |
References | (CONFIRM) http://docs.info.apple.com/article.html?artnum=305214 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/22183 - Broken Link, Vendor Advisory | |
References | (SLACKWARE) http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.592566 - Broken Link | |
References | (VUPEN) http://www.vupen.com/english/advisories/2006/4018 - Broken Link | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/29254 - Third Party Advisory, VDB Entry | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2006-0698.html - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/24805 - Broken Link, Vendor Advisory | |
References | (SECUNIA) http://secunia.com/advisories/22352 - Broken Link, Vendor Advisory | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2006-0697.html - Broken Link | |
References | (GENTOO) http://security.gentoo.org/glsa/glsa-200611-06.xml - Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/22362 - Broken Link, Vendor Advisory | |
References | (VUPEN) http://www.vupen.com/english/advisories/2006/4329 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/22196 - Broken Link, Vendor Advisory | |
References | (SECUNIA) http://secunia.com/advisories/24479 - Broken Link, Vendor Advisory | |
References | (FREEBSD) http://security.freebsd.org/advisories/FreeBSD-SA-06%3A22.openssh.asc - Third Party Advisory | |
References | (OPENPKG) http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.022-openssh.html - Broken Link | |
References | (DEBIAN) http://www.debian.org/security/2006/dsa-1212 - Broken Link | |
CVSS |
v2 : v3 : |
v2 : 9.3
v3 : 8.1 |
CPE | cpe:2.3:a:openbsd:openssh:2.9.9p2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:4.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.2.2p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.1p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.7:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.2.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:4.3:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.9:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.0.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.3:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:4.0p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.6:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.0.2p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.0:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:1.2.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.0.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:1.2.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.4:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.5.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:4.3p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.9.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.7.1p2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.5.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:4.2p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.8:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.5p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.4p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:1.2.27:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.8.1p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.6.1p2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.0p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.0.1p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.9p2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.9:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.3:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:4.1p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.7.1p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.3p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.5:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.5:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:1.2.3:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:4.0:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:1.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.6.1p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.7.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.6.1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.2.3p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.9.1p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:2.9p1:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:3.8.1:*:*:*:*:*:*:* |
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:* |
First Time |
Debian debian Linux
Debian Apple Apple mac Os X Apple mac Os X Server |
Information
Published : 2006-09-27 23:07
Updated : 2024-11-21 00:17
NVD link : CVE-2006-5051
Mitre link : CVE-2006-5051
CVE.ORG link : CVE-2006-5051
JSON object : View
Products Affected
apple
- mac_os_x_server
- mac_os_x
debian
- debian_linux
openbsd
- openssh
CWE
CWE-415
Double Free