Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-6387

Опубликовано: 01 июл. 2024
Источник: ubuntu
Приоритет: high
CVSS3: 8.1

Описание

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

РелизСтатусПримечание
devel

released

1:9.6p1-3ubuntu15
esm-infra-legacy/trusty

not-affected

introduced in v8.5p1
esm-infra/bionic

not-affected

introduced in v8.5p1
esm-infra/focal

not-affected

introduced in v8.5p1
esm-infra/xenial

not-affected

introduced in v8.5p1
fips-updates/bionic

not-affected

introduced in v8.5p1
fips-updates/focal

not-affected

introduced in v8.5p1
fips-updates/xenial

not-affected

introduced in v8.5p1
fips/bionic

not-affected

introduced in v8.5p1
fips/focal

not-affected

introduced in v8.5p1

Показывать по

РелизСтатусПримечание
devel

not-affected

introduced in v8.5p1
esm-apps/bionic

not-affected

introduced in v8.5p1
esm-apps/focal

not-affected

introduced in v8.5p1
esm-apps/jammy

not-affected

introduced in v8.5p1
esm-apps/noble

not-affected

introduced in v8.5p1
focal

not-affected

introduced in v8.5p1
jammy

not-affected

introduced in v8.5p1
mantic

not-affected

introduced in v8.5p1
noble

not-affected

introduced in v8.5p1
upstream

ignored

frozen on openssh 7.5p

Показывать по

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
12 месяцев назад

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS3: 8.1
nvd
12 месяцев назад

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS3: 8.1
msrc
11 месяцев назад

RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling

CVSS3: 8.1
debian
12 месяцев назад

A security regression (CVE-2006-5051) was discovered in OpenSSH's serv ...

suse-cvrf
12 месяцев назад

Security update for openssh

8.1 High

CVSS3