A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd).
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
What happened
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
Does it affect you
Not enough information
No products recorded, so this cannot be matched against anything.
What to do
- Follow the vendor advisory for the fixed release and any interim mitigation.
openssh.com - Apply the vendor patch named in this advisory.
openwall.com - Follow the vendor advisory for the fixed release and any interim mitigation.
ftp.netbsd.org - Apply the vendor patch named in this advisory.
github.com
Vendor's affected list
- ubuntu
- Exactly 23.10
- macos
- 12.0 up to the fix in 12.7.6
- rhel
- Exactly 9.0
Sources
A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.