CVE-2006-4924
sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 37.54% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- openbsd/openssh
- Source
- secalert@redhat.com
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:22.openssh.asc
- ftp://ftp.sco.com/pub/unixware7/714/security/p534336/p534336.txt
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc
- http://blogs.sun.com/security/entry/sun_alert_102962_security_vulnerability
- http://bugs.gentoo.org/show_bug.cgi?id=148228
- http://docs.info.apple.com/article.html?artnum=305214
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://marc.info/?l=openssh-unix-dev&m=115939141729160&w=2
- http://secunia.com/advisories/21923Vendor Advisory
- http://secunia.com/advisories/22091Vendor Advisory
- http://secunia.com/advisories/22116Vendor Advisory
- http://secunia.com/advisories/22158Vendor Advisory
- http://secunia.com/advisories/22164Vendor Advisory
- http://secunia.com/advisories/22183Vendor Advisory
- http://secunia.com/advisories/22196Vendor Advisory
- http://secunia.com/advisories/22208Vendor Advisory
- http://secunia.com/advisories/22236Vendor Advisory
- http://secunia.com/advisories/22245Vendor Advisory
- http://secunia.com/advisories/22270Vendor Advisory
- http://secunia.com/advisories/22298Vendor Advisory
- http://secunia.com/advisories/22352Vendor Advisory
- http://secunia.com/advisories/22362Vendor Advisory
- http://secunia.com/advisories/22487Vendor Advisory
- http://secunia.com/advisories/22495Vendor Advisory
- http://secunia.com/advisories/22823Vendor Advisory
- http://secunia.com/advisories/22926Vendor Advisory
- http://secunia.com/advisories/23038Vendor Advisory
- http://secunia.com/advisories/23241Vendor Advisory
- http://secunia.com/advisories/23340Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.