CVE-2006-5794

OpenSSH <4.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.

References (29)

Core 29
Core References
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-766
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017183
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22932
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22773
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22872
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22772
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4399
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23513
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23680
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_26_sr.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24055
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22771
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30120
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4400
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451100/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22778
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22814
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11840
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20956
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:204
Various Sources x_refsource_confirm
http://www.openssh.org/txt/release-4.5
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20061201-01-P.asc
Vendor Advisory vendor-advisory x_refsource_openpkg
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.032-openssh.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0738.html

Scores

EPSS 0.0301
EPSS Percentile 86.8%

Details

Status published
Products (1)
openbsd/openssh < 4.4
Published Nov 08, 2006
Tracked Since Feb 18, 2026