Vulnerability Description
packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | 4.5 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=148228ExploitPatch
- http://secunia.com/advisories/22245
- http://secunia.com/advisories/22298
- http://secunia.com/advisories/22495
- http://secunia.com/advisories/23038
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:179
- http://www.novell.com/linux/security/advisories/2006_24_sr.html
- http://www.novell.com/linux/security/advisories/2006_62_openssh.html
- http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/packet.c.diff?r1=1.144&r2=
- http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.022-openssh.html
- http://www.securityfocus.com/archive/1/447153/100/0/threaded
- http://www.securityfocus.com/archive/1/447861/100/200/threaded
- https://issues.rpath.com/browse/RPL-661
- https://issues.rpath.com/browse/RPL-681
- http://bugs.gentoo.org/show_bug.cgi?id=148228ExploitPatch
FAQ
What is CVE-2006-4925?
CVE-2006-4925 is a vulnerability with a CVSS score of 5.0 (MEDIUM). packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be N...
How severe is CVE-2006-4925?
CVE-2006-4925 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4925?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh.