CVE-2006-5051

HIGH

OpenSSH <4.4 - DoS

Title source: llm

Description

Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.

Exploits (3)

nomisec SCANNER 35 stars
by bigb0x · poc
https://github.com/bigb0x/CVE-2024-6387
nomisec SCANNER 2 stars
by sardine-web · poc
https://github.com/sardine-web/CVE-2024-6387_Check
nomisec SCANNER 2 stars
by anhvutuan · poc
https://github.com/anhvutuan/CVE-2024-6387-poc-1

Scores

CVSS v3 8.1
EPSS 0.0262
EPSS Percentile 85.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status draft

Affected Products (4)

openbsd/openssh < 4.4
debian/debian_linux
apple/mac_os_x < 10.3.9
apple/mac_os_x_server < 10.3.9

Timeline

Published Sep 27, 2006
Tracked Since Feb 18, 2026