CVE-2006-4925
packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL.
- Affected products
- Alt Linux, Opensuse, Openssh-Askpass
- Openbsd Openssh
- = 4.5
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 14.7% (96th percentile)
- NVD status
- Modified
- Published
- 2006-09-29
CVE-2006-4925 at NVD
No indexed exploits for CVE-2006-4925 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2006-4925 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.