VDB
CVE-2006-5794
CVE-2006-5794
PUBLISHED
CVSS 7.5 HIGH
Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.
EPSS 3.01% · 86.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
3.01%
86.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| openbsd | openssh | 0 |
Exploit Intelligence
- CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH. (github-poc)
- CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH. (github-poc)
- CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH. (github-poc)
- CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH. (github-poc)
- A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. (github-poc)
- A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. (github-poc)
- A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. (github-poc)
- A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. (github-poc)
- Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others. (github-poc)
- Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others. (github-poc)
…and 35 more exploits
Timeline
- Nov 8, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 20, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- None advisory
- 1017183 vdb
- http://sourceforge.net/project/shownotes.php?release_id=461854&group_id=69227 url
- 22932 third-party-advisory
- 22773 third-party-advisory
- http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html url
- http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227 url
- https://issues.rpath.com/browse/RPL-766 url
- 22872 third-party-advisory
- 22772 third-party-advisory
- ADV-2006-4399 vdb
- 23513 third-party-advisory
- 23680 third-party-advisory
- SUSE-SR:2006:026 vendor-advisory
- 24055 third-party-advisory
- 22771 third-party-advisory
- openssh-separation-verificaton-weakness(30120) vdb
- http://support.avaya.com/elmodocs2/security/ASA-2007-048.htm url
- ADV-2006-4400 vdb
- 20061109 rPSA-2006-0207-1 openssh openssh-client openssh-server mailing-list
…and 11 more