Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2x8c-95vh-gfv4

Опубликовано: 01 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A signal handler race condition was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().

A signal handler race condition was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().

Ссылки

EPSS

Процентиль: 98%
0.52037
Средний

8.1 High

CVSS3

Дефекты

CWE-362
CWE-364

Связанные уязвимости

CVSS3: 8.1
ubuntu
12 месяцев назад

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS3: 8.1
redhat
12 месяцев назад

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS3: 8.1
nvd
12 месяцев назад

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS3: 8.1
msrc
11 месяцев назад

RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling

CVSS3: 8.1
debian
12 месяцев назад

A security regression (CVE-2006-5051) was discovered in OpenSSH's serv ...

EPSS

Процентиль: 98%
0.52037
Средний

8.1 High

CVSS3

Дефекты

CWE-362
CWE-364