CVE-2006-4924
sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.
- Affected products
- Alt Linux, Hp-Ux, Openssh, Red Hat, Opensuse, Openssh-Askpass, Openssh-Askpass-Gnome, Openssh-Clients
- Openbsd Openssh
- = 1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.27, 2.1, 2.1.1, 2.2, 2.3, 2.5, 2.5.1, 2.5.2, 2.9, 2.9.9, 2.9.9p2, 2.9p1, 2.9p2, 3.0, 3.0.1, 3.0.1p1, 3.0.2, 3.0.2p1, 3.0p1, 3.1, 3.1p1, 3.2, 3.2.2, 3.2.2p1, 3.2.3p1, 3.3, 3.3p1, 3.4, 3.4p1, 3.5, 3.5p1, 3.6, 3.6.1, 3.6.1p1, 3.6.1p2, 3.7
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- EPSS
- 37.5% (98th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2006-09-27
CVE-2006-4924 at NVD
1 known exploit for CVE-2006-4924
Proof-of-concept code and exploit modules indexed by Sploitus