CVE-2006-5794
Last modified
CVE-2006-5794 is a vulnerability of currently unknown severity. Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.. EPSS estimates a 2.68% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | <= 4.4 |
References
- http://secunia.com/advisories/22771Patch, Vendor Advisory
- http://secunia.com/advisories/22773Patch, Vendor Advisory
- http://secunia.com/advisories/22771Patch, Vendor Advisory
- http://secunia.com/advisories/22773Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5794?
How severe is CVE-2006-5794?
How do I fix CVE-2006-5794?
Are you affected by CVE-2006-5794?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
